PostgreSQL Exporter Vulnerability in Canonical's PostgreSQL Operator
CVE-2026-104055
5.3MEDIUM
What is CVE-2026-104055?
A vulnerability exists in Canonical's PostgreSQL Operator where the Prometheus postgres_exporter logs the monitoring user's password in cleartext upon database connection errors. This exposure allows unauthorized actors with access to these logs to retrieve the password, potentially gaining read-only pg_monitor access to the PostgreSQL database. The issue has been addressed in multiple revisions across both the development and stable tracks, ensuring that user credentials are no longer compromised.
Affected Version(s)
postgresql-operator Linux 0 < 1189
postgresql-operator Linux 0 < 1190
postgresql-operator Linux 0 < 1216
