---
id: CVE-2026-104055
title: >-
  The postgresql-operator charm runs a Prometheus postgres_exporter to collect
  database metrics using a dedicated "monitoring" PostgreSQL user
summary: >-
  The postgresql-operator charm runs a Prometheus postgres_exporter to collect
  database metrics using a dedicated "monitoring" PostgreSQL user. On database
  connection errors, the exporter writes the monitoring user's password in
  cleartext …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-532
vendor: Canonical
product: charmed-postgresql
affected:
  - charmed-postgresql < 1189
  - charmed-postgresql < 1190
  - charmed-postgresql < 1216
  - charmed-postgresql < 1217
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T21:16:54.607'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104055'
references:
  - url: 'https://github.com/canonical/charmed-postgresql-snap/pull/305'
    label: security@ubuntu.com
  - url: 'https://github.com/canonical/charmed-postgresql-snap/pull/307'
    label: security@ubuntu.com
  - url: 'https://github.com/canonical/postgresql-operator/pull/1863'
    label: security@ubuntu.com
  - url: >-
      https://github.com/canonical/postgresql-operator/security/advisories/GHSA-rcx7-7rh5-r542
    label: security@ubuntu.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-02T22:33:09.846Z'
---

## Overview

The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicated "monitoring" PostgreSQL user. On database connection errors, the exporter writes the monitoring user's password in cleartext to its logs. Any actor able to read those logs can recover the password, which grants read-only pg_monitor access to PostgreSQL. This is fixed in the dev track (14/edge) in revisions 1189 (arm64) and 1190 (amd64), and in the stable track (14/stable) in revisions 1216 (arm64) and 1217 (amd64).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
