CVE-2026-6667
Estado: AnalizadaMedia (4.3)—
PgBouncer before 1.25.2 did not perform an appropriate authorization check for the KILL_CLIENT admin command. All users with access to the administration console (which itself requires authorization) could run this command. It would have been correct to allow only users listed in the admin_users parameter.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.33%
- Percentil entre todas las CVEs puntuadas: 24
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-862
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-6667",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-6667",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-05-11T14:44:31.243812Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
"affectedData": [
{
"vendor": "n/a",
"product": "PgBouncer",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1.25.2",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-05-09T01:16:09.287",
"references": [
{
"url": "https://www.pgbouncer.org/changelog.html#pgbouncer-125x",
"tags": [
"Release Notes"
],
"source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
"description": [
{
"lang": "en",
"value": "CWE-862"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "PgBouncer before 1.25.2 did not perform an appropriate authorization check for the KILL_CLIENT admin command. All users with access to the administration console (which itself requires authorization) could run this command. It would have been correct to allow only users listed in the admin_users parameter."
},
{
"lang": "es",
"value": "PgBouncer antes de 1.25.2 no realizaba una comprobación de autorización adecuada para el comando de administración KILL_CLIENT. Todos los usuarios con acceso a la consola de administración (que en sí misma requiere autorización) podían ejecutar este comando. Lo correcto habría sido permitir solo a los usuarios listados en el parámetro admin_users."
}
],
"lastModified": "2026-07-24T08:10:00.150",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:pgbouncer:pgbouncer:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FC45BB66-2289-466A-BC28-113710202BA5",
"versionEndExcluding": "1.25.2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"
}