Executive brief
pg_partman is a PostgreSQL extension that automates the management of time-based or ID-based table partitions. In versions prior to 5.5.0, the undo_partition() function fails to properly sanitize user-supplied configuration values, allowing an attacker with database access to execute arbitrary SQL commands with the privileges of whoever calls the function. This could lead to unauthorized data access, modification, or deletion.
Technical details
The undo_partition() function reads the part_config.time_encoder column without proper identifier quoting and interpolates it directly into a dynamically executed SELECT statement. A role with partman_user access can inject malicious SQL code instead of a function name. The vulnerability is exploited through direct function invocation by privileged callers, not through the background worker path, limiting automatic superuser escalation but still allowing abuse of available permissions.
Affected products
- pg_partman pg_partman before 5.5.0
Timeline
- 2026-09-18: disclosed: CVE-2026-61818 published
- 2026-07-22: patched: Fixed in version 5.5.0