CVE-2026-55769 - Overriding operators can lead to RCE - Mehmet Ince @mdisec - Vulnerability Researcher | Building security products | Security Advisor | Amateur Muay Thai fighter Skip to content Posts CVE INDEX About Me X LinkedIn YouTube GitHub CVE-2026-55769 – Overriding operators can lead to RCE Jun 18, 2026 Description The CloudNativePG (CNPG) instance manager opens superuser connections to managed PostgreSQL databases without pinning search_path in the connection startup packet. A role holding DATABASE OWNER on any managed database — a role CNPG creates by default at cluster bootstrap — can plant attacker-controlled overloads of built-in operators (for example =, >) in the public schema and re-target the database- or role-level search_path so those overloads resolve before pg_catalog. Vulnerability Information Product / Framework: CloudNative PostgreSQL Vendor Domain: cloudnative-pg.io Vulnerability Type: Misconfiguration CVE Details: View Full CVE Details → You may also enjoy… The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Appliance Jan 2026 Inside PostHog: How SSRF, a ClickHouse SQL Escaping 0day, and Default PostgreSQL Credentials Formed an RCE Chain (ZDI-25-099, ZDI-25-097, ZDI-25-096) Dec 2025 The Chessboard of Security: Insights on Product Development and Vulnerabilities from a Hacker Perspective Nov 2025 Digital Cosmos: A Journey Through the Galaxy of Vulnerabilities Oct 2025 CVE-2021-3825 | LiderAhenk 0day – All your PARDUS Clients Belongs To Me Dec 2021 Posts CVE INDEX About Me Search Search