PostgreSQL Exporter Vulnerability in Canonical's PostgreSQL Operator
CVE-2026-104055

5.3MEDIUM

Key Information:

Vendor

Canonical

Vendor
CVE Published:
2 October 2026

What is CVE-2026-104055?

A vulnerability exists in Canonical's PostgreSQL Operator where the Prometheus postgres_exporter logs the monitoring user's password in cleartext upon database connection errors. This exposure allows unauthorized actors with access to these logs to retrieve the password, potentially gaining read-only pg_monitor access to the PostgreSQL database. The issue has been addressed in multiple revisions across both the development and stable tracks, ensuring that user credentials are no longer compromised.

Affected Version(s)

postgresql-operator Linux 0 < 1189

postgresql-operator Linux 0 < 1190

postgresql-operator Linux 0 < 1216

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Allan Vidal
.