{"schema_version":1,"title":"CloudNativePG vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 3 vulnerabilities in CloudNativePG: 0 in the last 7 days and 2 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-55769, was published on 20 August 2026.","url":"https://junglewise.ai/threats/technologies/cloudnativepg","json_url":"https://junglewise.ai/threats/technologies/cloudnativepg.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/cloudnativepg","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":3,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":2,"last_365_days":3},"latest":[{"cve":"CVE-2026-55769","cvss":8.8,"epss":0.0077,"slug":"cve-2026-55769-cloudnativepg-privilege-escalation-via-search-path-manipulation","title":"CloudNativePG privilege escalation via search_path manipulation","severity":"info","exploited":false,"published_at":"2026-08-20T22:17:22.64+00:00","url":"https://junglewise.ai/threats/cve-2026-55769-cloudnativepg-privilege-escalation-via-search-path-manipulation"},{"cve":"CVE-2026-55765","cvss":8.5,"epss":0.005,"slug":"cve-2026-55765-cloudnativepg-cleartext-password-exposure-via-pg-stat-statements","title":"CloudNativePG cleartext password exposure via pg_stat_statements","severity":"high","exploited":false,"published_at":"2026-08-20T22:17:22.487+00:00","url":"https://junglewise.ai/threats/cve-2026-55765-cloudnativepg-cleartext-password-exposure-via-pg-stat-statements"},{"cve":"CVE-2026-44477","cvss":9.9,"epss":0.0052,"slug":"cve-2026-44477-cloudnativepg-privilege-escalation-and-rce-in-metrics-exporter","title":"CloudNativePG privilege escalation and RCE in metrics exporter","severity":"critical","exploited":false,"published_at":"2026-05-28T17:16:30.59+00:00","url":"https://junglewise.ai/threats/cve-2026-44477-cloudnativepg-privilege-escalation-and-rce-in-metrics-exporter"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"CloudNativePG","slug":"cloudnativepg","vendor":{"name":"CloudNativePG","slug":"cloudnativepg","url":"https://junglewise.ai/threats/vendors/cloudnativepg"},"aliases":[],"category":"database-management-system","homepage":"https://cloudnative-pg.io/","repo_url":"https://github.com/cloudnative-pg/cloudnative-pg","description":"An open-source operator designed to manage PostgreSQL workloads on Kubernetes clusters.","url":"https://junglewise.ai/threats/technologies/cloudnativepg"},"most_severe":[{"cve":"CVE-2026-44477","cvss":9.9,"epss":0.0052,"slug":"cve-2026-44477-cloudnativepg-privilege-escalation-and-rce-in-metrics-exporter","title":"CloudNativePG privilege escalation and RCE in metrics exporter","severity":"critical","exploited":false,"published_at":"2026-05-28T17:16:30.59+00:00","url":"https://junglewise.ai/threats/cve-2026-44477-cloudnativepg-privilege-escalation-and-rce-in-metrics-exporter"},{"cve":"CVE-2026-55765","cvss":8.5,"epss":0.005,"slug":"cve-2026-55765-cloudnativepg-cleartext-password-exposure-via-pg-stat-statements","title":"CloudNativePG cleartext password exposure via pg_stat_statements","severity":"high","exploited":false,"published_at":"2026-08-20T22:17:22.487+00:00","url":"https://junglewise.ai/threats/cve-2026-55765-cloudnativepg-cleartext-password-exposure-via-pg-stat-statements"},{"cve":"CVE-2026-55769","cvss":8.8,"epss":0.0077,"slug":"cve-2026-55769-cloudnativepg-privilege-escalation-via-search-path-manipulation","title":"CloudNativePG privilege escalation via search_path manipulation","severity":"info","exploited":false,"published_at":"2026-08-20T22:17:22.64+00:00","url":"https://junglewise.ai/threats/cve-2026-55769-cloudnativepg-privilege-escalation-via-search-path-manipulation"}],"generated_at":"2026-09-26T15:07:00.181821+00:00"}