An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add data source" feature to break out of the database context and execute shell commands on the underlying operating system.
References
Configurations
No configuration.
History
02 Apr 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-250 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.9 |
02 Apr 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-02 17:16
Updated : 2026-04-03 16:10
NVD link : CVE-2026-25212
Mitre link : CVE-2026-25212
CVE.ORG link : CVE-2026-25212
JSON object : View
Products Affected
No product.
CWE
CWE-250
Execution with Unnecessary Privileges
