Vulnerability record · CVE-2020-25695 · published 16 November 2020
CVE-2020-25695: PostgreSQL privilege escalation via object creation in schema
Postgresql · Postgresql
PostgreSQL before 13.1, 12.5, 11.10, 10.15, 9.6.20 and 9.5.24 allows a user with permission to create non-temporary objects in at least one schema to execute arbitrary SQL functions as a superuser. This is a privilege escalation that undermines the database's role separation and exposes all data and functions the superuser can reach.
Description
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with high confidentiality, integrity and availability impact and a very high EPSS percentile, though exploitation requires an authenticated account with schema creation rights.
What it is
PostgreSQL before 13.1, 12.5, 11.10, 10.15, 9.6.20 and 9.5.24 allows a user with permission to create non-temporary objects in at least one schema to execute arbitrary SQL functions as a superuser. This is a privilege escalation that undermines the database's role separation and exposes all data and functions the superuser can reach.
Impact
An attacker with a low-privileged database account gains superuser-level execution, compromising confidentiality, integrity and availability of the entire database instance.
Attack surface
Reachable over the network via normal database connections (CVSS AV:N) by an authenticated user holding CREATE rights on any schema; no user interaction is required.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is 0.4644 (98.8th percentile), indicating elevated predicted exploitation activity.
What to do
- Upgrade PostgreSQL to 13.1, 12.5, 11.10, 10.15, 9.6.20, 9.5.24 or later as applicable.
- Audit and revoke CREATE privileges on schemas from roles that do not require them.
- Apply the vendor and distribution advisories (Debian, Gentoo, NetApp) for packaged deployments.
- Restrict database network exposure and enforce least-privilege role design.
- Monitor for unexpected creation of functions or objects in schemas by non-administrative roles.
Detection
- Alert on CREATE FUNCTION or CREATE object events in schemas by roles that normally lack such rights.
- Review PostgreSQL logs for privilege changes or superuser-context execution originating from low-privileged sessions.
- Baseline schema object inventories and flag new non-temporary objects in unexpected schemas.
- Correlate database audit logs with authentication events for unusual role-to-superuser activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=1894425 | Issue TrackingThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2020/12/msg00005.html | Mailing ListThird Party Advisory |
| https://security.gentoo.org/glsa/202012-07 | Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20201202-0003/ | Third Party Advisory |
| https://www.postgresql.org/support/security/ | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=1894425 | Issue TrackingThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2020/12/msg00005.html | Mailing ListThird Party Advisory |
| https://security.gentoo.org/glsa/202012-07 | Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20201202-0003/ | Third Party Advisory |
| https://www.postgresql.org/support/security/ | Vendor Advisory |
Track CVE-2020-25695 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-25695), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.