CVE-2026-104055
Received Received - Intake

Information Disclosure in PostgreSQL Operator Charm

Vulnerability report for CVE-2026-104055, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Canonical Ltd.

Description

The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicated "monitoring" PostgreSQL user. On database connection errors, the exporter writes the monitoring user's password in cleartext to its logs. Any actor able to read those logs can recover the password, which grants read-only pg_monitor access to PostgreSQL. This is fixed in the dev track (14/edge) in revisions 1189 (arm64) and 1190 (amd64), and in the stable track (14/stable) in revisions 1216 (arm64) and 1217 (amd64).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
canonical postgresql_operator to 14.0.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The postgresql-operator charm uses a Prometheus postgres_exporter to collect database metrics with a dedicated monitoring PostgreSQL user. When database connection errors occur, the exporter logs the monitoring user's password in cleartext. Attackers with log access can retrieve this password, gaining read-only pg_monitor access to the PostgreSQL database.

Detection Guidance

Check PostgreSQL operator logs for the postgres_exporter component. Look for cleartext passwords in error messages or logs. Commands: journalctl -u postgresql-operator -n 100 --no-pager for systemd logs, or kubectl logs <pod-name> -n <namespace> for Kubernetes logs.

Impact Analysis

An attacker who gains access to the logs could obtain the monitoring user's password. This allows them to read database metrics and potentially access sensitive information, depending on the database's configuration and data stored.

Mitigation Strategies

Upgrade to fixed revisions: 14/edge revisions 1189 (arm64) or 1190 (amd64), or 14/stable revisions 1216 (arm64) or 1217 (amd64). Rotate the monitoring user password immediately after upgrade.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104055. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart