OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-61781

CRITICAL · CVSS 9.9 EPSS 0.80% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-18 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The pg_partman extension for PostgreSQL versions prior to 5.5.0 is vulnerable due to improper handling of user-defined SQL in the create_partition_time() function, allowing a role with partman_user privileges to execute arbitrary SQL commands with superuser privileges. This critical vulnerability can lead to database-wide compromise and operating-system command execution, making it imperative for organizations using affected versions to prioritize upgrading to version 5.5.0 or later to mitigate the risk. Database administrators and security teams should act swiftly to address this issue to protect sensitive data and maintain system integrity.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-61781
Severity
CRITICAL
CVSS
9.9
EPSS
0.80%

Original NVD Description

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_partition_time() reads the writable part_config.time_encoder text value and interpolates it without identifier quoting into a dynamically executed SELECT statement. A role with the documented partman_user INSERT and UPDATE privileges can store SQL rather than a function name. When pg_partman_bgw later creates a child partition for a text- or UUID-keyed set, the worker executes the stored SQL with pg_partman_bgw.role privileges, which default to PostgreSQL superuser. The persistent configuration row can repeatedly restore elevated access on later maintenance ticks, and successful exploitation can permit database-wide compromise and operating-system command execution as the PostgreSQL service account. This issue is fixed in version 5.5.0.