CVE-2026-92867: High severity Pgpool Pgpool-II vulnerability
Published Sep 30, 2026
·Updated
An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code execution.
Affected Software
1 affected component
Pgpool Pgpool-II
Event History
Sep 30, 2026
CVE Published
via MITRE·07:20 AM
Data Sourced
via MITRE·07:20 AM
DescriptionSeverity
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must be authenticated. The available data does not identify which Pgpool-II roles or privileges are sufficient.
2
What impact should operators plan for?
Successful exploitation may cause abnormal process termination or arbitrary code execution. The reported severity is high, with a CVSS score of 8.8.
3
Is exploitation possible remotely?
The vector is network-based and requires low attack complexity, with no user interaction required. An attacker must still have authenticated access.