Junglewise Threat Intelligence

CVE-2026-61819: pg_partman SQL injection and privilege escalation via jobmon

CVE-2026-61819 · Severity: high · CVSS 8.5 · Published 2026-09-18

Technologies: Pgpartman Pg Partman. Vendors: Pgpartman.

Executive brief

pg_partman is a PostgreSQL extension that manages partitioned tables automatically. A vulnerability in versions prior to 5.5.0 allows attackers to inject arbitrary SQL code when an exception occurs in certain functions, provided pg_jobmon is installed. If the background worker runs as a superuser (the default in older versions), the injected SQL executes with superuser privileges, enabling complete database compromise and command execution as the PostgreSQL service account.

Technical details

The vulnerability is a SQL injection flaw in exception handlers within pg_partman functions that construct SQL strings passed to pg_jobmon.add_job(). The p_parent_table parameter is inserted verbatim without proper escaping, allowing a partman_user to craft a parent table name containing a single quote that breaks out of the SQL literal and injects arbitrary code. The injected SQL executes in the context of pg_partman_bgw (the background worker), which defaults to PostgreSQL superuser privileges in affected versions. The malicious partition configuration persists and can re-trigger the vulnerability on subsequent maintenance operations.

Affected products

  • pgpartman pg_partman prior to 5.5.0

Timeline

  • 2026-09-18: disclosed: CVE-2026-61819 published
  • 2026-07-22: patched: Version 5.5.0 released with security fixes

References

Related threats