Junglewise Threat Intelligence

CVE-2026-44477: CloudNativePG privilege escalation and RCE in metrics exporter

CVE-2026-44477 · Severity: critical · CVSS 9.9 · Published 2026-05-28

Technologies: CloudNativePG. Vendors: Go, CloudNativePG.

Executive brief

CloudNativePG is an operator used to manage PostgreSQL database clusters within Kubernetes. A vulnerability in its monitoring component allows a low-privileged database user to escalate their privileges to a database superuser and execute arbitrary commands on the underlying operating system. This could lead to a complete takeover of the database pod and exposure of all hosted data.

Technical details

The CloudNativePG metrics exporter connects to PostgreSQL as the 'postgres' superuser but attempts to demote the session using 'SET ROLE'. Because 'session_user' remains 'postgres', any SQL expression evaluated during a scrape can invoke 'RESET ROLE' to regain superuser privileges. Attackers can exploit this by planting 'shadow' objects (functions or views) in a database that match unqualified identifiers used in monitoring queries (e.g., in default-monitoring.yaml). Once superuser status is regained, the attacker can use 'COPY ... TO PROGRAM' to achieve Remote Code Execution (RCE) as the 'postgres' user. The fix involves introducing a dedicated non-superuser role for the exporter and schema-qualifying all catalog references.

Affected products

  • CloudNativePG CloudNativePG < 1.28.3, >= 1.29.0, < 1.29.1

Timeline

  • 2026-05-08: disclosed
  • 2026-05-11: advisory

References