CVE-2026-25212
קריטית 9.9
תיאור (מקור, אנגלית)
An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add data source" feature to break out of the database context and execute shell commands on the underlying operating system.
מדדים
- CVSS 3.1
-
9.9 (CRITICAL)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-24/9/2026
- CWE
- CWE-250
מוצרים מושפעים
percona: monitoring and management
קישורים
- https://docs.percona.com/percona-monitoring-and-management/3/release-notes/3.7… Release NotesVendor Advisory
- https://percona.com Product