CRITICAL🇵🇱 Wersja polska

CVE-2026-44477

CVSS 9.4v4.0pub. 2026-05-28upd. 2026-06-30

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG metrics exporter opens its PostgreSQL connection as the postgres superuser via the pod-local Unix socket, then demotes the session with SET ROLE pg_monitor. SET ROLE changes only current_user; session_user remains postgres. Any SQL expression evaluated inside the scrape session can invoke RESET ROLE to recover real superuser privileges, then use COPY ... TO PROGRAM to spawn an OS-level subprocess as the postgres user inside the primary pod. The READ ONLY transaction flag does not block this; it gates writes to database state, not external processes. This vulnerability is fixed in 1.29.1 and 1.28.3.

🤖 AI Analysis
How it works

The CloudNativePG metrics exporter establishes a connection to PostgreSQL as the 'postgres' superuser via the pod's local socket, then reduces session privileges using the SET ROLE pg_monitor command. However, SET ROLE only changes current_user — session_user remains 'postgres'. Any SQL expression executed within the scraping session can invoke RESET ROLE, restoring full superuser privileges, after which the COPY ... TO PROGRAM command allows running any subprocess of the operating system as the 'postgres' user on the main pod. The READ ONLY transaction mechanism does not block this attack, as it only protects against writing to database state, not against running external processes.

Impact

An attacker can execute arbitrary system commands (OS-level command execution) as the 'postgres' user inside a Kubernetes pod, which may lead to database control compromise, violation of data confidentiality and integrity, and further lateral movement within the cluster environment.

Mitigation & patch

CloudNativePG should be updated to version 1.29.1 or 1.28.3, in which the vulnerability has been fixed. Patching is available in the official project repository.

Who is affected

CloudNativePG in versions earlier than 1.29.1 and 1.28.3

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Linuxfoundation Cloudnativepg

    APP
    Linuxfoundation
    < 1.28.31.29.0 – 1.29.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Container
CWE
References

Related vulnerabilities

CVE-2026-53488CRITICAL9.4PL ✓same vendor

containerd CRI plugin: brak walidacji etykiet obrazu umożliwia RCE na hoście

CVE-2026-37531CRITICAL9.8PL ✓same vendor

AGL app-framework-main: Zip Slip + TOCTOU umożliwiają zapis dowolnych plików

CVE-2026-32613CRITICAL9.9PL ✓same vendor

Spinnaker Echo: nieograniczony dostęp SPeL umożliwia RCE

CVE-2026-32604CRITICAL9.9PL ✓same vendor

RCE w Spinnaker — wykonanie dowolnych poleceń na podach clouddriver

CVE-2026-35171CRITICAL9.8PL ✓same vendor

RCE w Kedro przez niezabezpieczoną konfigurację logowania (dictConfig)