CVE-2026-61781
pg_partman has privilege escalation through SQL injection in create_partition_time()
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_partition_time() reads the writable part_config.time_encoder text value and interpolates it without identifier quoting into a dynamically executed SELECT statement. A role with the documented partman_user INSERT and UPDATE privileges can store SQL rather than a function name. When pg_partman_bgw later creates a child partition for a text- or UUID-keyed set, the worker executes the stored SQL with pg_partman_bgw.role privileges, which default to PostgreSQL superuser. The persistent configuration row can repeatedly restore elevated access on later maintenance ticks, and successful exploitation can permit database-wide compromise and operating-system command execution as the PostgreSQL service account. This issue is fixed in version 5.5.0.
| CWE | CWE-89 CWE-269 |
| Vendor | pgpartman |
| Product | pg_partman |
| Published | Sep 18, 2026 |
| Last Updated | Sep 18, 2026 |
Get instant alerts for pgpartman pg_partman
Be the first to know when new critical vulnerabilities affecting pgpartman pg_partman are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H