Executive brief
pg_partman is a PostgreSQL extension that manages partitioned tables automatically. A vulnerability in versions prior to 5.5.0 allows attackers to inject arbitrary SQL code when an exception occurs in certain functions, provided pg_jobmon is installed. If the background worker runs as a superuser (the default in older versions), the injected SQL executes with superuser privileges, enabling complete database compromise and command execution as the PostgreSQL service account.
Technical details
The vulnerability is a SQL injection flaw in exception handlers within pg_partman functions that construct SQL strings passed to pg_jobmon.add_job(). The p_parent_table parameter is inserted verbatim without proper escaping, allowing a partman_user to craft a parent table name containing a single quote that breaks out of the SQL literal and injects arbitrary code. The injected SQL executes in the context of pg_partman_bgw (the background worker), which defaults to PostgreSQL superuser privileges in affected versions. The malicious partition configuration persists and can re-trigger the vulnerability on subsequent maintenance operations.
Affected products
- pgpartman pg_partman prior to 5.5.0
Timeline
- 2026-09-18: disclosed: CVE-2026-61819 published
- 2026-07-22: patched: Version 5.5.0 released with security fixes