Executive brief
PGHoard, a tool used for managing PostgreSQL backups, contains a flaw where sensitive database credentials are saved in plain text within system logs. If an administrator enables debug-level logging, database usernames and passwords may be exposed to anyone with access to those log files. This could allow an unauthorized person with local system access to gain full control over the connected databases.
Technical details
PGHoard is vulnerable to CWE-532 (Insertion of Sensitive Information into Log File). When the application is configured to use .pgpass for authentication, it incorrectly includes database credentials in output generated at the debug logging level. An attacker with local access and sufficient privileges to read system or application logs can extract these credentials to gain unauthorized access to the PostgreSQL database. The vulnerability is present in versions prior to 2.7.1. Users are advised to upgrade to version 2.7.1 or greater, or as a temporary workaround, ensure that debug-level logging is disabled or filtered.
Affected products
- Aiven-Open pghoard < 2.7.1
Timeline
- 2026-06-17: disclosed
- 2026-06-18: advisory