๐Ÿ” CVE Alert

CVE-2026-44477

UNKNOWN 0.0

CloudNativePG: Metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG metrics exporter opens its PostgreSQL connection as the postgres superuser via the pod-local Unix socket, then demotes the session with SET ROLE pg_monitor. SET ROLE changes only current_user; session_user remains postgres. Any SQL expression evaluated inside the scrape session can invoke RESET ROLE to recover real superuser privileges, then use COPY ... TO PROGRAM to spawn an OS-level subprocess as the postgres user inside the primary pod. The READ ONLY transaction flag does not block this; it gates writes to database state, not external processes. This vulnerability is fixed in 1.29.1 and 1.28.3.

CWE CWE-250 CWE-271 CWE-426
Vendor cloudnative-pg
Product cloudnative-pg
Published May 28, 2026
Last Updated May 28, 2026
Stay Ahead of the Next One

Get instant alerts for cloudnative-pg cloudnative-pg

Be the first to know when new unknown vulnerabilities affecting cloudnative-pg cloudnative-pg are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

cloudnative-pg / cloudnative-pg
< 1.28.3 >= 1.29.0, < 1.29.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/cloudnative-pg/cloudnative-pg/security/advisories/GHSA-423p-g724-fr39 github.com: https://github.com/cloudnative-pg/cloudnative-pg/pull/10576