CVE-2026-25212: Critical severity Percona Percona PMM vulnerability
An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add data source" feature to break out of the database context and execute shell commands on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25212?
CVE-2026-25212 is considered a high-severity vulnerability due to its potential for authenticated remote code execution.
How do I fix CVE-2026-25212?
To mitigate CVE-2026-25212, upgrade to Percona PMM version 3.7 or later.
Who is affected by CVE-2026-25212?
Users of Percona PMM versions prior to 3.7 are vulnerable to CVE-2026-25212.
What types of attacks can be executed due to CVE-2026-25212?
CVE-2026-25212 allows attackers with pmm-admin rights to execute shell commands on the underlying operating system.
What are the prerequisites for exploiting CVE-2026-25212?
An attacker must have pmm-admin rights to exploit CVE-2026-25212 and utilize the "Add data source" feature.