9.9
CVE-2026-78155
- EPSS 0.27%
- Veröffentlicht 23.08.2026 10:16:28
- Zuletzt bearbeitet 16.09.2026 13:13:14
- Erkennungen
Untrusted Search Path in StackGres
privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.19 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cve@gitlab.com | 9.9 | 3.1 | 6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-426 Untrusted Search Path
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
https://gitlab.com/ongresinc/stackgres/-/work_items/3177