Executive brief
pg_partman is a PostgreSQL extension that automates the management of large partitioned tables. A privilege escalation flaw in versions before 5.5.0 allows database users with limited permissions to relocate table partitions into schemas they should not have access to, by exploiting the background worker's superuser privileges. This could enable unauthorized data access or table ownership takeover in multi-tenant database environments.
Technical details
The drop_partition_id() and drop_partition_time() functions bypass the standard ALTER TABLE SET SCHEMA authorization checks by accepting any retention schema name and executing the relocation under the pg_partman background worker's privileges (defaulting to PostgreSQL superuser). A partman_user role can specify a target schema where the role lacks CREATE privilege, and the superuser background worker performs the operation, bypassing normal PostgreSQL access controls. The fix in 5.5.0 requires that the retention schema be owned by the same role as the child table.
Affected products
- pgpartman pg_partman before 5.5.0
Timeline
- 2026-09-18: disclosed
- 2026-07-22: patched