CVE-2026-55765

Source
https://cve.org/CVERecord?id=CVE-2026-55765
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55765.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-55765
Aliases
  • GHSA-w3gf-xc94-wvmj
Downstream
Related
Published
2026-08-20T21:38:47.952Z
Modified
2026-08-22T03:49:46.265065761Z
Severity
  • 8.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
CloudNativePG: Cleartext role passwords recorded in pg_stat_statements allow privileged tenant roles to recover the PostgreSQL superuser credential and achieve RCE in the database pod
Details

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in ALTER ROLE and CREATE ROLE statements generated by SetUserPassword in pkg/management/postgres/utils/roles.go and appendPasswordOption in internal/management/controller/roles/postgres.go. When pgstatstatements was preloaded with trackutility enabled and an untrusted tenant held pgmonitor or pgreadall_stats, the tenant could recover platform-managed superuser or application-owner passwords, reconnect through enabled superuser TCP access, and execute operating system commands in the database pod with COPY ... FROM PROGRAM. Clusters using SCRAM-SHA-256 verifiers in managed-role Secrets were not affected. This issue is fixed in versions 1.28.4, 1.29.2, and 1.30.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-256",
        "CWE-522"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55765.json"
}
References

Affected packages

Git / github.com/cloudnative-pg/cloudnative-pg

Affected ranges

Type
GIT
Repo
https://github.com/cloudnative-pg/cloudnative-pg
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.28.4"
        },
        {
            "introduced": "1.29.0"
        },
        {
            "fixed": "1.29.2"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.0.1
v0.1.0
v0.2.0
v0.3.0
v0.4.0
v0.5.0
v0.6.0
v0.7.0
v0.8.0
v1.*
v1.0.0
v1.1.0
v1.10.0
v1.11.0
v1.12.0
v1.13.0
v1.14.0
v1.15.0
v1.15.1
v1.17.0
v1.18.0
v1.19.0
v1.2.0
v1.2.1
v1.20.0
v1.21.0
v1.23.0
v1.24.0
v1.24.0-rc1
v1.25.0
v1.25.0-rc1
v1.26.0
v1.26.0-rc1
v1.26.0-rc2
v1.26.0-rc3
v1.27.0
v1.27.0-rc1
v1.28.0
v1.28.0-rc1
v1.28.0-rc2
v1.28.1
v1.28.2
v1.28.3
v1.29.0
v1.29.1
v1.3.0
v1.30.0-rc1
v1.4.0
v1.5.0
v1.5.1
v1.6.0
v1.7.0
v1.7.1
v1.8.0
v1.9.0
v1.9.1
v1.9.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55765.json"