logo

Kubernetes Alert: 9.4 Severity RCE in CloudNativePG Enables PostgreSQL Superuser Takeover

ID: 82182126-1d91-521a-b600-2ea4da5624a7

STIX ID: report--82182126-1d91-521a-b600-2ea4da5624a7

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Ddos

...
...

**CVE-2026-44477 (CVSS 9.4): Critical privilege escalation and RCE in CloudNativePG's metrics exporter** — The exporter connects as the postgres superuser then attempts a superficial demotion (SET ROLE pg_monitor) that leaves session_user as postgres; an attacker can call RESET ROLE during metric scrapes (via shadowed functions or an unqualified pg_extensions call) to regain superuser and run OS commands as the postgres user. Patches (1.28.3, 1.29.1) and mitigations (dedicated non-superuser exporter role, schema-qualify functions, restrict DB ownership, limit scrape scope) are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.