CVE-2025-26701: Critical severity Percona PMM Server vulnerability
An issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can lead to SSH access, use of Sudo to root, and sensitive data exposure. This is fixed in PMM2 2.42.0-1.ova, 2.43.0-1.ova, 2.43.1-1.ova, 2.43.2-1.ova, and 2.44.0-1.ova and in PMM3 3.0.0-1.ova and later.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Percona PMM Server (OVA)to a version that resolves this vulnerability.Fixed in 2.42.0-1.ova - Upgrade
Upgrade
Percona PMM Server (OVA)to a version that resolves this vulnerability.Fixed in 2.43.0-1.ova - Upgrade
Upgrade
Percona PMM Server (OVA)to a version that resolves this vulnerability.Fixed in 2.43.1-1.ova - Upgrade
Upgrade
Percona PMM Server (OVA)to a version that resolves this vulnerability.Fixed in 2.43.2-1.ova - Upgrade
Upgrade
Percona PMM Server (OVA)to a version that resolves this vulnerability.Fixed in 2.44.0-1.ova - Upgrade
Upgrade
Percona PMM Server (OVA)to a version that resolves this vulnerability.Fixed in 3.0.0-1.ova
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26701?
CVE-2025-26701 is considered high severity due to its potential for unauthorized SSH access and root privileges.
How do I fix CVE-2025-26701?
To mitigate CVE-2025-26701, upgrade to PMM2 versions 2.42.0-1.ova and later, or PMM3 version 3.0.0-1.ova.
What vulnerability exists in CVE-2025-26701?
CVE-2025-26701 exposes default service account credentials that could allow unauthorized access and sensitive data exposure.
Which versions of Percona PMM Server are affected by CVE-2025-26701?
CVE-2025-26701 affects Percona PMM Server versions before 3.0.0-1.ova and PMM2 versions between 2.42.0-1.ova and 2.44.0-1.ova.
What are the consequences of CVE-2025-26701?
The consequences of CVE-2025-26701 include potential SSH access, root privileges via Sudo, and exposure of sensitive data.