Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104055— Monitoring-user password logged in cleartext by postgres_exporter in postgresql VM charm

Quick assessment

Affected
Canonical postgresql-operator
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

postgresql-operator charm 运行 Prometheus postgres_exporter,使用专用的“monitoring” PostgreSQL 用户收集数据库指标。在发生数据库连接错误时,导出器会将 monitoring 用户的密码以明文形式写入其日志。任何能够读取这些日志的攻击者均可恢复该密码,从而获得对 PostgreSQL 的只读 pg_monitor 访问权限。 该问题已在以下版本中修复: 开发轨道(dev track,14/edge):revision 1189(arm64)

CVSS 5.3 · Medium

Possible ATT&CK Techniques 1 AI

T1005 · Data from Local System
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104055

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Monitoring-user password logged in cleartext by postgres_exporter in postgresql VM charm
Source: CVE Program / CVE List V5
Vulnerability Description
The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicated "monitoring" PostgreSQL user. On database connection errors, the exporter writes the monitoring user's password in cleartext to its logs. Any actor able to read those logs can recover the password, which grants read-only pg_monitor access to PostgreSQL. This is fixed in the dev track (14/edge) in revisions 1189 (arm64) and 1190 (amd64), and in the stable track (14/stable) in revisions 1216 (arm64) and 1217 (amd64).
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过日志文件的信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Canonical postgresql-operator 0 ~ 1189 -

II. Public POCs for CVE-2026-104055

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104055

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-104055 (3)

Vendor Advisories for CVE-2026-104055 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-104055

No comments yet


Leave a comment