Executive brief
pg_partman is a PostgreSQL extension that automates the creation and management of partitioned tables. A flaw in versions before 5.5.0 allows a user with basic pg_partman privileges to inject arbitrary SQL code through a configuration field, which executes with elevated database privileges—potentially including superuser access when the maintenance background worker runs. An attacker could exploit this to compromise the entire database or execute operating system commands as the PostgreSQL service account.
Technical details
The vulnerability is a SQL injection in the part_config.time_dncoder field, where user-supplied text is interpolated directly into dynamic SQL without identifier quoting in functions such as run_maintenance(), show_partitions(), show_partition_info(), undo_partition(), and partition_data_time(). A partman_user with documented privileges can store malicious SQL instead of a decoder function name; when these functions or the background worker execute the poisoned value, the injected SQL runs with the operation's privileges. The fix in 5.5.0 properly quotes identifiers and implements Row Level Security controls, additionally changing the default background worker role from superuser to a restricted role.
Affected products
- pgpartman pg_partman prior to 5.5.0
Timeline
- 2026-09-18: disclosed
- 2026-07-22: patched: Version 5.5.0 released