CVE-2026-92869: High severity PgPool Global Development Group Pgpool-II vulnerability
Published Sep 30, 2026
·Updated
An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination.
Affected Software
1 affected component
PgPool Global Development Group Pgpool-II
Event History
Sep 30, 2026
CVE Published
via MITRE·07:21 AM
Data Sourced
via MITRE·07:21 AM
DescriptionSeverity
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
An attacker needs to be authenticated to Pgpool-II. The issue is remotely reachable and does not require user interaction.
2
What is the expected impact of successful exploitation?
Successful exploitation may cause abnormal process termination, resulting in an availability impact. The provided assessment does not indicate confidentiality or integrity impact.
3
Is a default Pgpool-II deployment affected?
The available information does not state whether the vulnerable condition is enabled or reachable in a default configuration.