Answer in brief
CVE-2026-104055 records a Medium severity (CVSS 5.3) vulnerability in Monitoring-user password logged in cleartext by postgres_exporter in postgresql VM charm. The current sources do not mark it as known exploited. The current feed maps Canonical/charmed-postgresql (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.3. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Canonical/charmed-postgresql (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Canonical/charmed-postgresqlgeneric | >=0 <1189 || >=0 <1190 || >=0 <1216 || >=0 <1217 | 1189, 1190, 1216, 1217 |
Published upstream
Oct 2, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 2, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 2, 2026
The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicated "monitoring" PostgreSQL user. On database connection errors, the exporter writes the monitoring user's password in cleartext to its logs. Any actor able to read those logs can recover the password, which grants read-only pg_monitor access to PostgreSQL. This is fixed in the dev track (14/edge) in revisions 1189 (arm64) and 1190 (amd64), and in the stable track (14/stable) in revisions 1216 (arm64) and 1217 (amd64).
Quoted source text, attributed separately from HOL analysis.