Impact
In pg_partman versions prior to 5.5.0, when the pg_jobmon extension is installed and the part_config.jobmon flag is true, certain exception handlers concatenate the p_parent_table value directly into an SQL string that calls pg_jobmon.add_job(). This flaw corresponds to the SQL Injection weakness type CWE‑89. A partman_user can create a parent table name containing a single quote, thereby terminating the literal and injecting arbitrary SQL. The injected code then executes with the privileges of the pg_partman_bgw role, which defaults to a PostgreSQL superuser. This allows the attacker to run arbitrary SQL statements and even launch operating‑system commands as the PostgreSQL service account, resulting in full database and system compromise.
Affected Systems
The vulnerability affects the pg_partman extension distributed by pgpartman. All releases earlier than version 5.5.0 are impacted when pg_jobmon is present and part_config.jobmon is set to true. Users who have installed older pg_partman packages and have enabled job monitoring should identify their current version and verify whether job monitoring is active.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity vulnerability. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, so current exploit prevalence is unknown. However, the attack path requires only the ability to create a parent table name with an embedded quote, a privilege that partman_user typically possesses. Once the injected SQL runs, it gains superuser rights and can execute system commands, which makes the exploitation vector highly dangerous. Repeat exploitation is possible because the vulnerable part_config row persists and can trigger further injection on subsequent maintenance ticks.
OpenCVE Enrichment