9.9

CVE-2026-78155

Exploit

Untrusted Search Path in StackGres

privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ongres ≫ Stackgres SwPlatform kubernetes Version < 1.19.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.19
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cve@gitlab.com 9.9 3.1 6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-426 Untrusted Search Path

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

https://gitlab.com/ongresinc/stackgres/-/work_items/3177
Vendor Advisory
Exploit
Mitigation