CVE-2026-92873: Medium severity PgPool Global Development Group Pgpool-II vulnerability
Published Sep 30, 2026
·Updated
Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node.
Affected Software
1 affected component
PgPool Global Development Group Pgpool-II
Event History
Sep 30, 2026
CVE Published
via MITRE·07:51 AM
Data Sourced
via MITRE·07:51 AM
DescriptionSeverity
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The issue may be exploitable by an unauthenticated attacker. The provided CVSS vector indicates network access, low attack complexity, and no user interaction or privileges required.
2
What is the likely impact if exploitation succeeds?
An attacker may be able to promote an arbitrary Pgpool-II watchdog node to the leader role. The supplied severity data indicates limited confidentiality, integrity, and availability impact.