Executive brief
pg_partman is a PostgreSQL extension that automates management of time-based or ID-based partitioned tables. A privilege escalation vulnerability allows users with standard partman role permissions to inject SQL code into the partition configuration, which is then executed with superuser privileges by the background maintenance worker. An attacker with documented INSERT/UPDATE privileges can achieve database-wide compromise and execute arbitrary operating-system commands as the PostgreSQL service account.
Technical details
The create_partition_time() function interpolates the time_encoder configuration value directly into a dynamically executed SELECT statement without identifier quoting, allowing SQL injection. A user with partman_user documented privileges can store arbitrary SQL instead of a function name in the writable part_config.time_encoder field. When pg_partman_bgw background worker creates child partitions for text or UUID-keyed sets, it executes the injected SQL with superuser-level privileges (default configuration). The persistent configuration row enables repeated privilege escalation across maintenance cycles.
Affected products
- pg_partman pg_partman before 5.5.0
Timeline
- 2026-09-18: disclosed
- 2026-07-22: patched