Description
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance() handles exceptions outside the loop that processes rows from part_config, so an exception for one partition set immediately terminates the loop and skips every later set. A role with partman_user access can insert or update a row that reliably fails and assign it a low maintenance_order value so it is processed before legitimate rows. Repeated maintenance ticks then abort before legitimate partition sets are maintained, causing database-wide loss of automated partition maintenance. This issue is fixed in version 5.5.0.
Published: 2026-09-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Availability Loss
Action: Patch Immediately
AI Analysis

Impact

The vulnerability resides in the pg_partman PostgreSQL extension, which manages partitioned tables for time or ID based partitioning. The run_maintenance function processes rows from the part_config table, but before version 5.5.0 it exits the loop when any exception occurs outside the row‑processing loop. An attacker who possesses partman_user privileges can insert or update a row that intentionally triggers an exception, assigning it a low maintenance_order so that it is processed first. Each subsequent maintenance tick then aborts before legitimate partition sets are maintained, causing a loss of automated partition maintenance throughout the database. This defect effectively degrades database availability and reliability as partitions are not periodically maintained, potentially leading to performance degradation or data inconsistency.

Affected Systems

Products impacted include the pgpartman pg_partman extension for PostgreSQL. Versions earlier than 5.5.0 are vulnerable; the issue is resolved in version 5.5.0 and later.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity impact, with no EPSS score available so the exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires access to a role with partman_user privileges and the ability to modify the part_config table, implying a local or privileged database attack vector. Given the medium severity and the need for specific role permissions, the overall risk is moderate, but should be mitigated promptly by applying the vendor fix.

Generated by OpenCVE AI on September 19, 2026 at 11:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade pg_partman to version 5.5.0 or later to correct the error handling in run_maintenance.
  • Review and restrict partman_user privileges to limit the ability to insert exception‑triggering rows into part_config.
  • During the transition period, consider disabling automatic maintenance or monitoring maintenance ticks to prevent repeated failures until the patch is applied.

Generated by OpenCVE AI on September 19, 2026 at 11:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Pgpartman
Pgpartman pg Partman
Vendors & Products Pgpartman
Pgpartman pg Partman

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance() handles exceptions outside the loop that processes rows from part_config, so an exception for one partition set immediately terminates the loop and skips every later set. A role with partman_user access can insert or update a row that reliably fails and assign it a low maintenance_order value so it is processed before legitimate rows. Repeated maintenance ticks then abort before legitimate partition sets are maintained, causing database-wide loss of automated partition maintenance. This issue is fixed in version 5.5.0.
Title pg_partman disable maintenance for all partition sets
Weaknesses CWE-703
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Pgpartman Pg Partman
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-24T21:05:26.895Z

Reserved: 2026-07-10T20:17:57.992Z

Link: CVE-2026-61822

cve-icon Vulnrichment

Updated: 2026-09-24T21:03:57.821Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T20:17:20.363

Modified: 2026-09-24T21:17:18.580

Link: CVE-2026-61822

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:24:45Z

Weaknesses
  • CWE-703

    Improper Check or Handling of Exceptional Conditions