CVE-2026-44477 | cloudnative-pg CloudNativePG up to 1.28.2/1.29.0 Transaction unnecessary privileges (GHSA-423p-g724-fr39)
A vulnerability was found in cloudnative-pg CloudNativePG up to 1.28.2/1.29.0. It has been classified as critical. The impacted element is an unknown function of the component Transaction Handler. The manipulation leads to execution with unnecessary privileges.
This vulnerability is documented as CVE-2026-44477. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.