Description
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, inherit_template_properties() manually surrounds primary-key column names from pg_attribute.attname with double quotes without escaping embedded double-quote characters. A partman_user who owns a template table can create a crafted column name that breaks out of the generated ALTER TABLE ADD PRIMARY KEY identifier when the background worker applies the key to a child partition. The generated SQL then executes with pg_partman_bgw.role privileges, which default to PostgreSQL superuser, permitting database-wide compromise and operating-system command execution as the PostgreSQL service account. The crafted catalog identifier persists until removed and can trigger again during later partition creation. This issue is fixed in version 5.5.0.
Published: 2026-09-18
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation with potential OS Command Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an SQL injection flaw in pg_partman’s inherit_template_properties() function. A partman_user who owns a template table can craft a column name that contains double‑quotes. When the background worker applies a primary key to a new child partition, the unescaped identifier is embedded into an ALTER TABLE ADD PRIMARY KEY statement. That statement is executed with the privileges of pg_partman_bgw.role, which by default is a PostgreSQL superuser. The flaw therefore allows a non‑superuser to gain superuser privileges inside the database and, because the background worker runs with server‑process privileges, to execute operating‑system commands as the PostgreSQL service account. This is an instance of CWE‑89. Affected systems The issue affects the pg_partman PostgreSQL extension, named pg_partman, in all releases prior to version 5.5.0. There are no further product version sub‑details in the CNA data, but the official advisory states that the fix is introduced in v5.5.0. Risk and exploitability The CVSS score is 8.5, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is based on a privilege escalation within the database: a partman_user must have the ability to create or modify a template table. Once a malicious column name is inserted, subsequent partition creation triggers the injection. Because the error occurs when the background worker fires, the exploit does not require network or remote access; it can be executed locally by any user with the necessary role. The resulting compromise spans the entire database and can lead to arbitrary operating‑system command execution. Mitigation and Remediation

Affected Systems

pg_partman (pgpartman:pg_partman), any PostgreSQL database using the extension with a version older than 5.5.0.

Risk and Exploitability

High severity CVSS 8.5; EPSS not available; not in KEV. The vulnerability can be exploited by a partman_user who owns a template table. The exploit escalates privileges to a superuser and permits OS command execution through the background worker. No external media is required.

Generated by OpenCVE AI on September 19, 2026 at 11:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade pg_partman to version 5.5.0 or later, which fixes the SQL escaping bug.
  • If an upgrade is not possible immediately, change the pg_partman_bgw.role to a non‑superuser or revoke its superuser privileges.
  • Audit existing template tables for maliciously crafted column names and remove any that contain unescaped double‑quotes.

Generated by OpenCVE AI on September 19, 2026 at 11:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Pgpartman
Pgpartman pg Partman
Vendors & Products Pgpartman
Pgpartman pg Partman

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, inherit_template_properties() manually surrounds primary-key column names from pg_attribute.attname with double quotes without escaping embedded double-quote characters. A partman_user who owns a template table can create a crafted column name that breaks out of the generated ALTER TABLE ADD PRIMARY KEY identifier when the background worker applies the key to a child partition. The generated SQL then executes with pg_partman_bgw.role privileges, which default to PostgreSQL superuser, permitting database-wide compromise and operating-system command execution as the PostgreSQL service account. The crafted catalog identifier persists until removed and can trigger again during later partition creation. This issue is fixed in version 5.5.0.
Title pg_partman privilege escalation via SQL injection when inheriting template properties
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Pgpartman Pg Partman
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-22T15:39:45.442Z

Reserved: 2026-07-10T20:17:57.992Z

Link: CVE-2026-61820

cve-icon Vulnrichment

Updated: 2026-09-22T15:39:39.243Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T20:17:20.067

Modified: 2026-09-23T18:28:25.093

Link: CVE-2026-61820

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:24:41Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')