Kubernetes Alert: 9.4 Severity RCE in CloudNativePG Enables PostgreSQL Superuser Takeover
ID: 82182126-1d91-521a-b600-2ea4da5624a7
STIX ID: report--82182126-1d91-521a-b600-2ea4da5624a7
Feed Name: securityonline.info
**CVE-2026-44477 (CVSS 9.4): Critical privilege escalation and RCE in CloudNativePG's metrics exporter** — The exporter connects as the postgres superuser then attempts a superficial demotion (SET ROLE pg_monitor) that leaves session_user as postgres; an attacker can call RESET ROLE during metric scrapes (via shadowed functions or an unqualified pg_extensions call) to regain superuser and run OS commands as the postgres user. Patches (1.28.3, 1.29.1) and mitigations (dedicated non-superuser exporter role, schema-qualify functions, restrict DB ownership, limit scrape scope) are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
