Description
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, when pg_jobmon is installed and part_config.jobmon is true, exception handlers in multiple pg_partman functions place p_parent_table verbatim inside a SQL string literal used to call pg_jobmon.add_job(). A partman_user can create a parent-table name containing a single quote that terminates the literal and injects SQL when an affected exception path runs. If pg_partman_bgw reaches that path, the injected SQL executes with pg_partman_bgw.role privileges, which default to PostgreSQL superuser, permitting database-wide compromise and operating-system command execution as the PostgreSQL service account. The persistent part_config row can trigger the escalation again on later maintenance ticks. This issue is fixed in version 5.5.0.
Published: 2026-09-18
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

In pg_partman versions prior to 5.5.0, when the pg_jobmon extension is installed and the part_config.jobmon flag is true, certain exception handlers concatenate the p_parent_table value directly into an SQL string that calls pg_jobmon.add_job(). This flaw corresponds to the SQL Injection weakness type CWE‑89. A partman_user can create a parent table name containing a single quote, thereby terminating the literal and injecting arbitrary SQL. The injected code then executes with the privileges of the pg_partman_bgw role, which defaults to a PostgreSQL superuser. This allows the attacker to run arbitrary SQL statements and even launch operating‑system commands as the PostgreSQL service account, resulting in full database and system compromise.

Affected Systems

The vulnerability affects the pg_partman extension distributed by pgpartman. All releases earlier than version 5.5.0 are impacted when pg_jobmon is present and part_config.jobmon is set to true. Users who have installed older pg_partman packages and have enabled job monitoring should identify their current version and verify whether job monitoring is active.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity vulnerability. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, so current exploit prevalence is unknown. However, the attack path requires only the ability to create a parent table name with an embedded quote, a privilege that partman_user typically possesses. Once the injected SQL runs, it gains superuser rights and can execute system commands, which makes the exploitation vector highly dangerous. Repeat exploitation is possible because the vulnerable part_config row persists and can trigger further injection on subsequent maintenance ticks.

Generated by OpenCVE AI on September 19, 2026 at 11:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade pg_partman to version 5.5.0 or later to eliminate the SQL injection flaw.
  • If upgrading immediately is not possible, disable the pg_jobmon extension or set part_config.jobmon to false so the vulnerable exception path is never reached.
  • Restrict partman_user to the minimum privileges required for its operations, ensuring it cannot create parent tables that can trigger the injection pathway.

Generated by OpenCVE AI on September 19, 2026 at 11:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Pgpartman
Pgpartman pg Partman
Vendors & Products Pgpartman
Pgpartman pg Partman

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, when pg_jobmon is installed and part_config.jobmon is true, exception handlers in multiple pg_partman functions place p_parent_table verbatim inside a SQL string literal used to call pg_jobmon.add_job(). A partman_user can create a parent-table name containing a single quote that terminates the literal and injects SQL when an affected exception path runs. If pg_partman_bgw reaches that path, the injected SQL executes with pg_partman_bgw.role privileges, which default to PostgreSQL superuser, permitting database-wide compromise and operating-system command execution as the PostgreSQL service account. The persistent part_config row can trigger the escalation again on later maintenance ticks. This issue is fixed in version 5.5.0.
Title pg_partman privilege escalation via SQL injection in when using pg_jobmon and encountering exception
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Pgpartman Pg Partman
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T20:17:50.708Z

Reserved: 2026-07-10T20:17:57.992Z

Link: CVE-2026-61819

cve-icon Vulnrichment

Updated: 2026-09-18T20:17:46.372Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T20:17:19.927

Modified: 2026-09-23T18:12:04.247

Link: CVE-2026-61819

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:24:40Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')