CVE-2026-44477Disclosure(linuxfoundation / cloudnativepg)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch linuxfoundation cloudnativepg systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG metrics exporter opens its PostgreSQL connection as the postgres superuser via the pod-local Unix socket, then demotes the session with SET ROLE pg_monitor. SET ROLE changes only current_user; session_user remains postgres. Any SQL expression evaluated inside the scrape session can invoke RESET ROLE to recover real superuser privileges, then use COPY ... TO PROGRAM to spawn an OS-level subprocess as the postgres user inside the primary pod. The READ ONLY transaction flag does not block this; it gates writes to database state, not external processes. This vulnerability is fixed in 1.29.1 and 1.28.3.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-250CWE-271CWE-426

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cloudnativepg

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 5d ago at 1 mentions (2026-05-11); latest day: 1
  • 6 total mentions across 6 days

Affected systems

Products
cloudnativepg

Deep dive

Activity timeline6 mentions / 6d
00111Mentions · 2026-05-11: 1Mentions · 2026-05-15: 1Mentions · 2026-05-18: 1Mentions · 2026-05-28: 1Mentions · 2026-05-29: 1Mentions · 2026-08-11: 1PoC Mentioned / Linked · 2026-05-18: 1Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-15: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-15: 1Technical Details · 2026-05-18: 1Technical Details · 2026-05-28: 1Technical Details · 2026-05-29: 1Technical Details · 2026-08-11: 105-1105-1505-1805-2805-2908-11
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
General
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-111
Patch1
2026-05-151
Patch1
2026-05-181
Disclosure1
2026-05-281
General1
2026-05-291
Disclosure1
2026-08-111
Disclosure1
Full discourse6 posts
  • Gray Hats@the_yellow_fall
    Patch

    CVE-2026-44477 in CloudNativePG allows low-privilege users to gain root-level RCE via metrics exporters. Update to version 1.29.1 or 1.28.3 now! #CloudNativePG #Kubernetes #PostgreSQL #CyberSecurity #InfoSec #RCE #K8s #VulnerabilityAlert #CloudNative https://securityonline.info/cloudnativepg-vulnerability-cve-2026-44477-postgresql-rce/ https://t.co/vWjIo3ICcr

    Post summary

    CVE‑2026‑44477 allows low‑privilege users to achieve root‑level RCE via metrics exporters; users should update to CloudNativePG 1.29.1 or 1.28.3.

    01082436
    12.5K followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: A critical privilege escalation #vulnerability in #CloudNativePG allows an authenticated attacker to gain superuser privileges and execute arbitrary OS commands inside the primary pod. #CVE-2026-44477 CVSS(4.0): 9.4. #Patch #Patch #Patch

    Post summary

    The post warns of a critical privilege escalation flaw in CloudNativePG (CVE-2026-44477) with a high CVSS score but offers no PoC, exploit code, or explicit patch details.

    01000225
    7.2K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical - CloudNativePG Metrics Exporter Privilege Escalation (CVE-2026-44477) CloudNativePG contains a vulnerability in the metrics exporter where PostgreSQL sessions can retain elevated identity, enabling privilege escalation through query execution paths. Under certain conditions, this can allow escalation to superuser context and execution of OS-level commands inside the database pod. The issue may be exploitable via crafted metric queries or default monitoring configurations. 👉 Affected: cloudnative-pg < 1.28.3 | 1.29.01 👉 Fix: Upgrade to 1.28.3 or 1.29.1 and review monitoring configuration and query permissions

    Post summary

    CVE-2026-44477 is a privilege‑escalation flaw in CloudNativePG’s metrics exporter, allowing PostgreSQL sessions to gain superuser rights and execute OS commands. Patching to version 1.28.3 or 1.29.1 and reviewing monitoring configurations mitigates the risk.

    0000191
    187 followersView on X
  • Donweb Media@DonwebMedia
    Disclosure

    Si usás CloudNativePG en prod: hay un CVE (CVSS 9.4) que deja escalar de rol normal a superusuario de Postgres. Chequeá tu versión. https://cloud.donweb.com/cloudnativepg-cve-2026-44477-de-rol-comun-a-superuser-de-postgres/ #Ciberseguridad #PostgreSQL

    Post summary

    Alert announces CVE-2026-44477 in CloudNativePG that allows privilege escalation, urging users to verify their version.

    0000037
    6 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-44477: Metrics exporter privilege escalation - What It Means for Your Business and How to Respond https://hubs.li/Q04j98m60

    Post summary

    The article’s title indicates a privilege‑escalation vulnerability (CVE‑2026‑44477) in a metrics exporter, but offers no PoC, exploit details, patch information, or evidence of active exploitation.

    0000032
    31 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    CloudNativePGの重大な脆弱性 CVE-2026-44477、Kubernetes上のPostgreSQLで権限昇格とPod内RCEの恐れ https://rocket-boys.co.jp/security-measures-lab/cloudnativepg-cve-2026-44477-pod-rce-kubernetes/ #セキュリティ対策Lab #security #securitynews

    Post summary

    The post announces a new critical vulnerability (CVE‑2026‑44477) in CloudNativePG, noting privilege escalation and pod‑level RCE potential on Kubernetes, and links to a detailed analysis.

    00000132
    407 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationcloudnativepg-kubernetes-

Explore more