CVE-2026-78155: Untrusted Search Path in StackGres
Published Aug 23, 2026
·Updated
privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges
Affected Software
1 affected component
StackGres operator
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
StackGresto a version that resolves this vulnerability.Fixed in 1.19.0
Event History
Aug 23, 2026
CVE Published
via MITRE·09:26 AM
Data Sourced
via MITRE·09:26 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A low-privilege tenant who owns a database can exploit the privilege-escalation flaw.
2
What access does an attacker need?
The attacker needs low-privilege access and ownership of a database. No user interaction is required, and the vulnerability is remotely exploitable according to the provided vector.
3
What is the potential impact if exploitation succeeds?
Successful exploitation allows the tenant to gain administrator privileges. The reported impact includes high confidentiality, integrity, and availability impact.