CVE-2026-44477
CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE in github.com/cloudnative-pg/cloudnative-pg
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/cloudnative-pg/cloudnative-pg/security/advisories/GHSA-423p-g724-fr39, https://nvd.nist.gov/vuln/detail/CVE-2026-44477, https://github.com/cloudnative-pg/cloudnative-pg/pull/10576, https://github.com/cloudnative-pg/cloudnative-pg/releases/tag/v1.28.3, https://github.com/cloudnative-pg/cloudnative-pg/releases/tag/v1.29.1