๐Ÿ” CVE Alert

CVE-2026-44477

HIGH 8.8

CloudNativePG: Metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG metrics exporter opens its PostgreSQL connection as the postgres superuser via the pod-local Unix socket, then demotes the session with SET ROLE pg_monitor. SET ROLE changes only current_user; session_user remains postgres. Any SQL expression evaluated inside the scrape session can invoke RESET ROLE to recover real superuser privileges, then use COPY ... TO PROGRAM to spawn an OS-level subprocess as the postgres user inside the primary pod. The READ ONLY transaction flag does not block this; it gates writes to database state, not external processes. This vulnerability is fixed in 1.29.1 and 1.28.3.

CWE CWE-250 CWE-271 CWE-426
Vendor cloudnative-pg
Product cloudnative-pg
Published May 28, 2026
Last Updated Jul 15, 2026
Stay Ahead of the Next One

Get instant alerts for cloudnative-pg cloudnative-pg

Be the first to know when new high vulnerabilities affecting cloudnative-pg cloudnative-pg are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

cloudnative-pg / cloudnative-pg
< 1.28.3 >= 1.29.0, < 1.29.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/cloudnative-pg/cloudnative-pg/security/advisories/GHSA-423p-g724-fr39 github.com: https://github.com/cloudnative-pg/cloudnative-pg/pull/10576 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-44477 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2482763 security.access.redhat.com: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44477.json