pg_partman 是一个用于通过时间或 ID 管理 PostgreSQL 分区表的扩展。在 5.5.0 之前, 、 、 、 和 函数会将可写的 文本值未加标识符引号地插入到动态 SQL 中。拥有文档中所述的 权限的角色可以存储 SQL 语句,而不仅仅是解码器函数名。当受影响的后续操作使用被污染的该值时(包括针对基于文本或 UUID 键集的 维护任务),该 SQL 将以执行该操作的权限运行,而该权限可能是默认的 PostgreSQL 超级用户后台工作进程(background worker)角色。由于持久化的行可
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| pgpartman | pg_partman | < 5.5.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pgpartman | pg_partman | < 5.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61781 | 9.9 CRITICAL | pg_partman has privilege escalation through SQL injection in create_partition_time() |
| CVE-2026-61820 | 8.5 HIGH | pg_partman privilege escalation via SQL injection when inheriting template properties |
| CVE-2026-61818 | 8.5 HIGH | pg_partman SQL injection in undo partition time encoder |
| CVE-2026-61819 | 8.5 HIGH | pg_partman privilege escalation via SQL injection in when using pg_jobmon and encountering |
| CVE-2026-61821 | 8.5 HIGH | pg_partman authorization bypass to move child tables between schemas during retention |
| CVE-2026-61822 | 6.5 MEDIUM | pg_partman disable maintenance for all partition sets |
No comments yet