PatchSiren

cloudnative-pg CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL cloudnative-pg CVE published 2026-08-20

CVE-2026-55769

A critical vulnerability in CloudNativePG, a platform for managing PostgreSQL databases within Kubernetes environments, allows an attacker to gain superuser access. This issue, tracked as CVE-2026-55769, arises from the platform's failure to pin the search_path in certain functions, enabling a role with DATABASE OWNER privileges to execute attacker-controlled functions as the postgres superuser. The vulne [truncated]

HIGH cloudnative-pg CVE published 2026-08-20

CVE-2026-55765

CVE-2026-55765 debrief: CloudNativePG vulnerability allows untrusted tenants to recover platform-managed superuser or application-owner passwords and execute operating system commands through `COPY ... FROM PROGRAM` when pg_stat_statements is preloaded with track_utility enabled. Clusters using SCRAM-SHA-256 verifiers in managed-role Secrets were not affected. Defenders managing Kubernetes environments us [truncated]