← Back to search

CVE-2026-61781

9.9 CRITICALpublic exploit available

Published 2026-09-18 · Updated 2026-09-23

AI risk analysis

Summary
The flaw allows a role with specific privileges to execute arbitrary SQL, leading to potential database-wide compromise and OS command execution.
Exploitability
Exploitation is moderately hard as it requires a role with partman_user INSERT and UPDATE privileges and knowledge of the SQL injection vulnerability. Precondition is the presence of a writable part_config.time_encoder value.
Blast radius
If exploited, the impact could be severe, potentially leading to full database compromise and execution of arbitrary OS commands.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to pg_partman version 5.5.0 or later.
rcesql-injectionpostgrespartitioned-tables

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_partition_time() reads the writable part_config.time_encoder text value and interpolates it without identifier quoting into a dynamically executed SELECT statement. A role with the documented partman_user INSERT and UPDATE privileges can store SQL rather than a function name. When pg_partman_bgw later creates a child partition for a text- or UUID-keyed set, the worker executes the stored SQL with pg_partman_bgw.role privileges, which default to PostgreSQL superuser. The persistent configuration row can repeatedly restore elevated access on later maintenance ticks, and successful exploitation can permit database-wide compromise and operating-system command execution as the PostgreSQL service account. This issue is fixed in version 5.5.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-89, CWE-269

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.