Junglewise Threat Intelligence

CVE-2026-61818: pg_partman undo_partition SQL injection

CVE-2026-61818 · Severity: high · CVSS 8.5 · Published 2026-09-18

Executive brief

pg_partman is a PostgreSQL extension that automates the management of time-based or ID-based table partitions. In versions prior to 5.5.0, the undo_partition() function fails to properly sanitize user-supplied configuration values, allowing an attacker with database access to execute arbitrary SQL commands with the privileges of whoever calls the function. This could lead to unauthorized data access, modification, or deletion.

Technical details

The undo_partition() function reads the part_config.time_encoder column without proper identifier quoting and interpolates it directly into a dynamically executed SELECT statement. A role with partman_user access can inject malicious SQL code instead of a function name. The vulnerability is exploited through direct function invocation by privileged callers, not through the background worker path, limiting automatic superuser escalation but still allowing abuse of available permissions.

Affected products

  • pg_partman pg_partman before 5.5.0

Timeline

  • 2026-09-18: disclosed: CVE-2026-61818 published
  • 2026-07-22: patched: Fixed in version 5.5.0

References

Related threats