CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

[NEW] [high] pg_partman: Multiple vulnerabilities

highCVE-2026-61822CVE-2026-61821CVE-2026-61781CVE-2026-61817CVE-2026-61818CVE-2026-61819
A remote, authenticated attacker can exploit multiple vulnerabilities in pg_partman to perform a denial of service attack, bypass authorization, and conduct SQL injection attacks, allowing them to gain elevated privileges and execute arbitrary operating system commands.

CSIRTS triage

What
Multiple vulnerabilities allow a remote, authenticated attacker to perform denial of service, bypass authorization, and conduct SQL injection attacks.
Who is affected
Authenticated users of pg_partman are affected.
Urgency
Remediation is high urgency due to the potential for severe exploitation.
Action
Patch to the latest version of pg_partman to address these vulnerabilities.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch pg_partman

Get an email when a new pg_partman advisory drops — max one per day, one-click unsubscribe.

Details

Source
CERT-Bund (BSI) Security Advisories (DE · national-cert · site)
Severity
high
Published
2026-07-23
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2493

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-61822coverage & exploitation statusNVD · CVE.org
CVE-2026-61821coverage & exploitation statusNVD · CVE.org
CVE-2026-61781coverage & exploitation statusNVD · CVE.org
CVE-2026-61817coverage & exploitation statusNVD · CVE.org
CVE-2026-61818coverage & exploitation statusNVD · CVE.org
CVE-2026-61819coverage & exploitation statusNVD · CVE.org
CVE-2026-61820coverage & exploitation statusNVD · CVE.org

More from CERT-Bund (BSI) Security Advisories