是一个用于按时间或 ID 管理分区表的 PostgreSQL 扩展。在 5.5.0 之前的版本中, 函数将 作为无限制的文本读取,并在动态执行的 SELECT 语句中直接插值(未对标识符进行引用/转义)。拥有 访问权限的角色可以在 中存储 SQL 语句而非函数名,该 SQL 将以调用 的调用者权限执行。 该函数不属于默认的后台工作进程(background-worker)执行路径,这限制了与相关“创建分区”漏洞中描述的自动超级用户权限提升的影响范围;但具有较高权限的调用者仍可被利用,导致其可用的机密性、完整性和可用
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| pgpartman | pg_partman | < 5.5.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pgpartman | pg_partman | < 5.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61781 | 9.9 CRITICAL | pg_partman has privilege escalation through SQL injection in create_partition_time() |
| CVE-2026-61820 | 8.5 HIGH | pg_partman privilege escalation via SQL injection when inheriting template properties |
| CVE-2026-61817 | 8.5 HIGH | pg_partman privilege escalation via SQL injection in several functions via time decoder |
| CVE-2026-61819 | 8.5 HIGH | pg_partman privilege escalation via SQL injection in when using pg_jobmon and encountering |
| CVE-2026-61821 | 8.5 HIGH | pg_partman authorization bypass to move child tables between schemas during retention |
| CVE-2026-61822 | 6.5 MEDIUM | pg_partman disable maintenance for all partition sets |
No comments yet