Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-55769: CloudNativePG can let a database owner gain superuser rights
CVE-2026-55769 · published 1 month ago
Summary
Versions of CloudNativePG before the latest updates allow a user who owns a database to change how queries are run, letting them execute code as the system’s superuser. This can lead to running operating‑system commands and accessing sensitive credentials inside the container. Upgrade to the newest release of CloudNativePG to close the gap and prevent this elevated access.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| cloudnative-pg | cloudnative-pg | < 1.28.4 |
Original advisory text
CloudNativePG: Overriding operators can lead to privilege escalation in CloudNativePG for SQL queries without a fixed `search_path`
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG opened superuser connections without pinning search_path in fillDefaultParameters in pkg/management/postgres/pool/profiles.go. A role holding DATABASE OWNER could create overloaded built-in operators in the public schema and change the database or role search_path, causing instance-manager introspection queries such as SELECT COUNT(*) > 0 FROM pg_catalog.pg_extension WHERE extname = $1 to execute attacker-controlled functions as the postgres superuser. The same trust issue affected direct sql.Open("pgx", ...) callsites and the public.user_search SECURITY DEFINER function, enabling PostgreSQL superuser access, operating system command execution through COPY ... FROM PROGRAM, and access to the pod ServiceAccount token. This issue is fixed in versions 1.28.4, 1.29.2, and 1.30.0.
References
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55769... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-55769 Vendor Advisory
- https://github.com/cloudnative-pg/cloudnative-pg/releases/tag/v1.28.4 URL
- https://github.com/cloudnative-pg/cloudnative-pg/releases/tag/v1.29.2 URL
- https://github.com/cloudnative-pg/cloudnative-pg/releases/tag/v1.30.0 URL
- https://github.com/cloudnative-pg/cloudnative-pg/security/advisories/GHSA-x8c2-3... Vendor Advisory
- https://github.com/cloudnative-pg/cloudnative-pg/commit/02b5c6289b7609dc87fcb1ae... Patch
- https://github.com/cloudnative-pg/cloudnative-pg/commit/db38f4d80315c8f1b21bf511... Patch
- https://github.com/cloudnative-pg/cloudnative-pg/commit/e0e2d53adbd907a61f583b14... Patch
- https://github.com/cloudnative-pg/cloudnative-pg/pull/10774 Patch
Severity
9.4
Critical
CVSS 4.0: 9.4 (OSV)
Exploitation
EPSS <1%
Type
CWE-426Untrusted Search Path
Timeline
Published20 Aug 2026
Updated27 Sep 2026
First seen20 Aug 2026
Track software like this
Free during beta