{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44477.json"
      }
    ],
    "title": "github.com/cloudnative-pg/cloudnative-pg: CloudNativePG: Metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE",
    "tracking": {
      "current_release_date": "2026-07-02T13:09:46+00:00",
      "generator": {
        "date": "2026-07-02T13:09:46+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.1"
        }
      },
      "id": "CVE-2026-44477",
      "initial_release_date": "2026-05-28T15:46:12.241000+00:00",
      "revision_history": [
        {
          "date": "2026-05-28T15:46:12.241000+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-06-11T09:06:10+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-07-02T13:09:46+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Openshift Data Foundation 4",
                "product": {
                  "name": "Red Hat Openshift Data Foundation 4",
                  "product_id": "red_hat_openshift_data_foundation_4",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Openshift Data Foundation 4"
          },
          {
            "category": "product_version",
            "name": "odf4/devicefinder-rhel9",
            "product": {
              "name": "odf4/devicefinder-rhel9",
              "product_id": "odf4/devicefinder-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/devicefinder-rhel9?repository_url=registry.redhat.io/odf4/devicefinder-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "odf4/mcg-rhel9-operator",
            "product": {
              "name": "odf4/mcg-rhel9-operator",
              "product_id": "odf4/mcg-rhel9-operator",
              "product_identification_helper": {
                "purl": "pkg:oci/mcg-rhel9-operator?repository_url=registry.redhat.io/odf4/mcg-rhel9-operator"
              }
            }
          },
          {
            "category": "product_version",
            "name": "odf4/ocs-metrics-exporter-rhel9",
            "product": {
              "name": "odf4/ocs-metrics-exporter-rhel9",
              "product_id": "odf4/ocs-metrics-exporter-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/ocs-metrics-exporter-rhel9?repository_url=registry.redhat.io/odf4/ocs-metrics-exporter-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "odf4/ocs-rhel9-operator",
            "product": {
              "name": "odf4/ocs-rhel9-operator",
              "product_id": "odf4/ocs-rhel9-operator",
              "product_identification_helper": {
                "purl": "pkg:oci/ocs-rhel9-operator?repository_url=registry.redhat.io/odf4/ocs-rhel9-operator"
              }
            }
          },
          {
            "category": "product_version",
            "name": "odf4/odf-cli-rhel9",
            "product": {
              "name": "odf4/odf-cli-rhel9",
              "product_id": "odf4/odf-cli-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/odf-cli-rhel9?repository_url=registry.redhat.io/odf4/odf-cli-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "odf4/odf-cloudnative-pg-rhel9-operator",
            "product": {
              "name": "odf4/odf-cloudnative-pg-rhel9-operator",
              "product_id": "odf4/odf-cloudnative-pg-rhel9-operator",
              "product_identification_helper": {
                "purl": "pkg:oci/odf-cloudnative-pg-rhel9-operator?repository_url=registry.redhat.io/odf4/odf-cloudnative-pg-rhel9-operator"
              }
            }
          },
          {
            "category": "product_version",
            "name": "odf4/odf-multicluster-rhel9-operator",
            "product": {
              "name": "odf4/odf-multicluster-rhel9-operator",
              "product_id": "odf4/odf-multicluster-rhel9-operator",
              "product_identification_helper": {
                "purl": "pkg:oci/odf-multicluster-rhel9-operator?repository_url=registry.redhat.io/odf4/odf-multicluster-rhel9-operator"
              }
            }
          },
          {
            "category": "product_version",
            "name": "odf4/odf-rhel9-operator",
            "product": {
              "name": "odf4/odf-rhel9-operator",
              "product_id": "odf4/odf-rhel9-operator",
              "product_identification_helper": {
                "purl": "pkg:oci/odf-rhel9-operator?repository_url=registry.redhat.io/odf4/odf-rhel9-operator"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "odf4/devicefinder-rhel9 as a component of Red Hat Openshift Data Foundation 4",
          "product_id": "red_hat_openshift_data_foundation_4:odf4/devicefinder-rhel9"
        },
        "product_reference": "odf4/devicefinder-rhel9",
        "relates_to_product_reference": "red_hat_openshift_data_foundation_4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "odf4/mcg-rhel9-operator as a component of Red Hat Openshift Data Foundation 4",
          "product_id": "red_hat_openshift_data_foundation_4:odf4/mcg-rhel9-operator"
        },
        "product_reference": "odf4/mcg-rhel9-operator",
        "relates_to_product_reference": "red_hat_openshift_data_foundation_4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "odf4/ocs-metrics-exporter-rhel9 as a component of Red Hat Openshift Data Foundation 4",
          "product_id": "red_hat_openshift_data_foundation_4:odf4/ocs-metrics-exporter-rhel9"
        },
        "product_reference": "odf4/ocs-metrics-exporter-rhel9",
        "relates_to_product_reference": "red_hat_openshift_data_foundation_4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "odf4/ocs-rhel9-operator as a component of Red Hat Openshift Data Foundation 4",
          "product_id": "red_hat_openshift_data_foundation_4:odf4/ocs-rhel9-operator"
        },
        "product_reference": "odf4/ocs-rhel9-operator",
        "relates_to_product_reference": "red_hat_openshift_data_foundation_4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "odf4/odf-cli-rhel9 as a component of Red Hat Openshift Data Foundation 4",
          "product_id": "red_hat_openshift_data_foundation_4:odf4/odf-cli-rhel9"
        },
        "product_reference": "odf4/odf-cli-rhel9",
        "relates_to_product_reference": "red_hat_openshift_data_foundation_4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "odf4/odf-cloudnative-pg-rhel9-operator as a component of Red Hat Openshift Data Foundation 4",
          "product_id": "red_hat_openshift_data_foundation_4:odf4/odf-cloudnative-pg-rhel9-operator"
        },
        "product_reference": "odf4/odf-cloudnative-pg-rhel9-operator",
        "relates_to_product_reference": "red_hat_openshift_data_foundation_4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "odf4/odf-multicluster-rhel9-operator as a component of Red Hat Openshift Data Foundation 4",
          "product_id": "red_hat_openshift_data_foundation_4:odf4/odf-multicluster-rhel9-operator"
        },
        "product_reference": "odf4/odf-multicluster-rhel9-operator",
        "relates_to_product_reference": "red_hat_openshift_data_foundation_4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "odf4/odf-rhel9-operator as a component of Red Hat Openshift Data Foundation 4",
          "product_id": "red_hat_openshift_data_foundation_4:odf4/odf-rhel9-operator"
        },
        "product_reference": "odf4/odf-rhel9-operator",
        "relates_to_product_reference": "red_hat_openshift_data_foundation_4"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-44477",
      "cwe": {
        "id": "CWE-250",
        "name": "Execution with Unnecessary Privileges"
      },
      "discovery_date": "2026-05-28T17:01:09.448577+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "red_hat_openshift_data_foundation_4:odf4/devicefinder-rhel9",
            "red_hat_openshift_data_foundation_4:odf4/odf-rhel9-operator"
          ]
        },
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "red_hat_openshift_data_foundation_4:odf4/mcg-rhel9-operator"
          ]
        },
        {
          "label": "component_not_present",
          "product_ids": [
            "red_hat_openshift_data_foundation_4:odf4/odf-cli-rhel9"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2482763"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in CloudNativePG's metrics exporter. The issue arises because the metrics exporter connected to PostgreSQL using a highly privileged account and did not properly restrict privileges during monitoring operations. A low-privileged database user could exploit this behavior through crafted monitoring queries or PostgreSQL object resolution manipulation to regain PostgreSQL superuser privileges and potentially execute arbitrary operating system commands as the postgres user inside the affected database pod.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "github.com/cloudnative-pg/cloudnative-pg: CloudNativePG: Metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This vulnerability affects CloudNativePG's monitoring and metrics export functionality. The attacker may exploit the affected monitoring functionality to escalate privileges within the PostgreSQL environment and potentially execute arbitrary operating system commands as the postgres user inside the affected database pod.\n \nRed Hat Product Security has rated this issue as an Important severity vulnerability rather than Critical.\n\nA successful exploitation requires access to a valid database account. A low-privileged authenticated database user (PR:L) is needed.\n\nAlthough exploitation may result in PostgreSQL superuser access and command execution within the affected pod, the impact remains limited to the affected PostgreSQL and container environment. It does not lead to container escape, Kubernetes cluster compromise, or host level privilege escalation. Therefore, Scope is assessed as Unchanged (S:U).\n\nBecause successful exploitation may allow disclosure, modification, or disruption of database contents, as well as arbitrary command execution within the affected pod, Red Hat assessed the Confidentiality, Integrity, and Availability impacts as High (C:H/I:H/A:H).",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "red_hat_openshift_data_foundation_4:odf4/ocs-metrics-exporter-rhel9",
          "red_hat_openshift_data_foundation_4:odf4/ocs-rhel9-operator",
          "red_hat_openshift_data_foundation_4:odf4/odf-cloudnative-pg-rhel9-operator",
          "red_hat_openshift_data_foundation_4:odf4/odf-multicluster-rhel9-operator"
        ],
        "known_not_affected": [
          "red_hat_openshift_data_foundation_4:odf4/devicefinder-rhel9",
          "red_hat_openshift_data_foundation_4:odf4/mcg-rhel9-operator",
          "red_hat_openshift_data_foundation_4:odf4/odf-cli-rhel9",
          "red_hat_openshift_data_foundation_4:odf4/odf-rhel9-operator"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-44477"
        },
        {
          "category": "external",
          "summary": "RHBZ#2482763",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482763"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-44477",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44477"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-44477",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44477"
        },
        {
          "category": "external",
          "summary": "https://github.com/cloudnative-pg/cloudnative-pg/pull/10576",
          "url": "https://github.com/cloudnative-pg/cloudnative-pg/pull/10576"
        },
        {
          "category": "external",
          "summary": "https://github.com/cloudnative-pg/cloudnative-pg/security/advisories/GHSA-423p-g724-fr39",
          "url": "https://github.com/cloudnative-pg/cloudnative-pg/security/advisories/GHSA-423p-g724-fr39"
        }
      ],
      "release_date": "2026-05-28T15:46:12.241000+00:00",
      "remediations": [
        {
          "category": "workaround",
          "details": "- Avoid using unqualified identifiers in custom monitoring queries\n- Restrict ownership of user-controlled schemas and database objects\n- Avoid unnecessary exposure of monitoring query configuration to untrusted users\n- Avoid using broad monitoring configurations such as: ``` target_databases: '*' ``` unless all databases and users are trusted.",
          "product_ids": [
            "red_hat_openshift_data_foundation_4:odf4/ocs-metrics-exporter-rhel9",
            "red_hat_openshift_data_foundation_4:odf4/ocs-rhel9-operator",
            "red_hat_openshift_data_foundation_4:odf4/odf-cloudnative-pg-rhel9-operator",
            "red_hat_openshift_data_foundation_4:odf4/odf-multicluster-rhel9-operator"
          ]
        },
        {
          "category": "none_available",
          "details": "Affected",
          "product_ids": [
            "red_hat_openshift_data_foundation_4:odf4/ocs-metrics-exporter-rhel9",
            "red_hat_openshift_data_foundation_4:odf4/ocs-rhel9-operator",
            "red_hat_openshift_data_foundation_4:odf4/odf-cloudnative-pg-rhel9-operator",
            "red_hat_openshift_data_foundation_4:odf4/odf-multicluster-rhel9-operator"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "red_hat_openshift_data_foundation_4:odf4/devicefinder-rhel9",
            "red_hat_openshift_data_foundation_4:odf4/mcg-rhel9-operator",
            "red_hat_openshift_data_foundation_4:odf4/ocs-metrics-exporter-rhel9",
            "red_hat_openshift_data_foundation_4:odf4/ocs-rhel9-operator",
            "red_hat_openshift_data_foundation_4:odf4/odf-cli-rhel9",
            "red_hat_openshift_data_foundation_4:odf4/odf-cloudnative-pg-rhel9-operator",
            "red_hat_openshift_data_foundation_4:odf4/odf-multicluster-rhel9-operator",
            "red_hat_openshift_data_foundation_4:odf4/odf-rhel9-operator"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "red_hat_openshift_data_foundation_4:odf4/devicefinder-rhel9",
            "red_hat_openshift_data_foundation_4:odf4/mcg-rhel9-operator",
            "red_hat_openshift_data_foundation_4:odf4/ocs-metrics-exporter-rhel9",
            "red_hat_openshift_data_foundation_4:odf4/ocs-rhel9-operator",
            "red_hat_openshift_data_foundation_4:odf4/odf-cli-rhel9",
            "red_hat_openshift_data_foundation_4:odf4/odf-cloudnative-pg-rhel9-operator",
            "red_hat_openshift_data_foundation_4:odf4/odf-multicluster-rhel9-operator",
            "red_hat_openshift_data_foundation_4:odf4/odf-rhel9-operator"
          ]
        }
      ],
      "title": "github.com/cloudnative-pg/cloudnative-pg: CloudNativePG: Metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE"
    }
  ]
}