CVE-2026-92868

Summary

An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificate authentication.

Affected Software

VendorProductVersion RangeStatus
Pgpool Global Development GroupPgpool-II4.7.0 <= 4.7.2affected
Pgpool Global Development GroupPgpool-II4.6.0 <= 4.6.7affected
Pgpool Global Development GroupPgpool-II4.5.0 <= 4.5.12affected
Pgpool Global Development GroupPgpool-II4.4.0 <= 4.4.17affected
Pgpool Global Development GroupPgpool-II4.3.0 <= 4.3.20affected
Pgpool Global Development GroupPgpool-II4.0.x <= 4.2.xaffected

Weaknesses

  • CWE-295: Improper certificate validation

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References