Executive brief
CloudNativePG is an operator used to manage PostgreSQL database clusters within Kubernetes. A vulnerability in its monitoring component allows a low-privileged database user to escalate their privileges to a database superuser and execute arbitrary commands on the underlying operating system. This could lead to a complete takeover of the database pod and exposure of all hosted data.
Technical details
The CloudNativePG metrics exporter connects to PostgreSQL as the 'postgres' superuser but attempts to demote the session using 'SET ROLE'. Because 'session_user' remains 'postgres', any SQL expression evaluated during a scrape can invoke 'RESET ROLE' to regain superuser privileges. Attackers can exploit this by planting 'shadow' objects (functions or views) in a database that match unqualified identifiers used in monitoring queries (e.g., in default-monitoring.yaml). Once superuser status is regained, the attacker can use 'COPY ... TO PROGRAM' to achieve Remote Code Execution (RCE) as the 'postgres' user. The fix involves introducing a dedicated non-superuser role for the exporter and schema-qualifying all catalog references.
Affected products
- CloudNativePG CloudNativePG < 1.28.3, >= 1.29.0, < 1.29.1
Timeline
- 2026-05-08: disclosed
- 2026-05-11: advisory