CVE-2026-92873

Summary

Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node.

Affected Software

VendorProductVersion RangeStatus
Pgpool Global Development GroupPgpool-II4.7.0 <= 4.7.2affected
Pgpool Global Development GroupPgpool-II4.6.0 <= 4.6.7affected
Pgpool Global Development GroupPgpool-II4.5.0 <= 4.5.12affected
Pgpool Global Development GroupPgpool-II4.4.0 <= 4.4.17affected
Pgpool Global Development GroupPgpool-II4.3.0 <= 4.3.20affected
Pgpool Global Development GroupPgpool-II3.5.x <= 4.2.xaffected

Weaknesses

  • CWE-303: Incorrect Implementation of Authentication Algorithm

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References