TROYANOSYVIRUS
Retour aux CVEs

CVE-2026-6667

MEDIUM
4.3

Description

PgBouncer before 1.25.2 did not perform an appropriate authorization check for the KILL_CLIENT admin command. All users with access to the administration console (which itself requires authorization) could run this command. It would have been correct to allow only users listed in the admin_users parameter.

Details CVE

Score CVSS v3.14.3
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurNONE
Publie5/9/2026
Derniere modification5/9/2026
Sourcenvd
Observations honeypot0

Faiblesses (CWE)

CWE-862

References

https://www.pgbouncer.org/changelog.html#pgbouncer-125x(f86ef6dc-4d3a-42ad-8f28-e6d5547a5007)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.