Search

Find a vulnerability

Search criteria

    1 vulnerability found for postgresql-operator by Canonical

    CVE-2026-104055 (GCVE-0-2026-104055)

    Vulnerability from cvelistv5 – Published: 2026-10-02 20:35 – Updated: 2026-10-03 15:52
    VLAI
    Title
    Monitoring-user password logged in cleartext by postgres_exporter in postgresql VM charm
    Summary
    The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicated "monitoring" PostgreSQL user. On database connection errors, the exporter writes the monitoring user's password in cleartext to its logs. Any actor able to read those logs can recover the password, which grants read-only pg_monitor access to PostgreSQL. This is fixed in the dev track (14/edge) in revisions 1189 (arm64) and 1190 (amd64), and in the stable track (14/stable) in revisions 1216 (arm64) and 1217 (amd64).
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:50 UTC
    CWE
    • CWE-532 - Insertion of sensitive information into log file
    Impacted products
    Vendor Product Version
    Canonical postgresql-operator Affected: 0 , < 1189 (charm-revision)
    Affected: 0 , < 1190 (charm-revision)
    Affected: 0 , < 1216 (charm-revision)
    Affected: 0 , < 1217 (charm-revision)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104055",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:50:41.564616Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:52:55.087Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://charmhub.io/postgresql",
              "defaultStatus": "unaffected",
              "packageName": "charmed-postgresql",
              "platforms": [
                "Linux"
              ],
              "product": "postgresql-operator",
              "repo": "https://github.com/canonical/postgresql-operator",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "1189",
                  "status": "affected",
                  "version": "0",
                  "versionType": "charm-revision"
                },
                {
                  "lessThan": "1190",
                  "status": "affected",
                  "version": "0",
                  "versionType": "charm-revision"
                },
                {
                  "lessThan": "1216",
                  "status": "affected",
                  "version": "0",
                  "versionType": "charm-revision"
                },
                {
                  "lessThan": "1217",
                  "status": "affected",
                  "version": "0",
                  "versionType": "charm-revision"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Allan Vidal"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicated \"monitoring\" PostgreSQL user. On database connection errors, the exporter writes the monitoring user\u0027s password in cleartext to its logs. Any actor able to read those logs can recover the password, which grants read-only pg_monitor access to PostgreSQL. This is fixed in the dev track (14/edge) in revisions 1189 (arm64) and 1190 (amd64), and in the stable track (14/stable) in revisions 1216 (arm64) and 1217 (amd64)."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-37",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-37 Retrieve Embedded Sensitive Data"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-532",
                  "description": "CWE-532 Insertion of sensitive information into log file",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T20:35:50.514Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/canonical/postgresql-operator/security/advisories/GHSA-rcx7-7rh5-r542"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/postgresql-operator/pull/1863"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/charmed-postgresql-snap/pull/305"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/charmed-postgresql-snap/pull/307"
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "Monitoring-user password logged in cleartext by postgres_exporter in postgresql VM charm",
          "x_generator": {
            "engine": "cvelib 1.8.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-104055",
        "datePublished": "2026-10-02T20:35:50.514Z",
        "dateReserved": "2026-10-01T18:01:17.865Z",
        "dateUpdated": "2026-10-03T15:52:55.087Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }