CVE-2026-78155

9.9

OnGres · StackGres

The StackGres operator is vulnerable to privilege escalation, allowing a low-privilege tenant who owns a database to gain administrator privileges.

Executive summary

The StackGres operator contains a critical privilege escalation flaw that allows low-privileged users to gain full administrator access to the system.

Vulnerability

The vulnerability is classified as an untrusted search path issue (CWE-426). It allows an authenticated user with low privileges to escalate their access level to that of an administrator within the StackGres environment.

Business impact

This vulnerability poses a major threat to multi-tenant environments, as it allows for total system compromise by a single compromised tenant account. Given the CVSS score of 9.9, the potential for unauthorized administrative access constitutes a catastrophic security failure for affected infrastructures.

Remediation

Immediate Action: Upgrade the StackGres operator to version 1.19.0 as recommended by the vendor.

Proactive Monitoring: Audit logs for administrative privilege changes and monitor for unexpected activity associated with low-privileged service accounts or tenant roles.

Compensating Controls: Restrict access to the StackGres management interface to trusted internal networks and implement strict Role-Based Access Control (RBAC) policies until the patch is applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the extreme severity of this privilege escalation vulnerability, immediate remediation is required to maintain the integrity of the StackGres deployment. Administrators should prioritize the upgrade to version 1.19.0 to prevent unauthorized escalation and potential total system takeover.

More OnGres CVEs