PgBouncer before 1.25.2 did not perform an appropriate authorization check for the KILL_CLIENT admin command. All users with access to the administration console (which itself requires authorization) could run this command. It would have been correct to allow only users listed in the admin_users parameter.
References
| Link | Resource |
|---|---|
| https://www.pgbouncer.org/changelog.html#pgbouncer-125x | Release Notes |
Configurations
History
14 May 2026, 18:49
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.pgbouncer.org/changelog.html#pgbouncer-125x - Release Notes | |
| First Time |
Pgbouncer
Pgbouncer pgbouncer |
|
| CPE | cpe:2.3:a:pgbouncer:pgbouncer:*:*:*:*:*:*:*:* |
09 May 2026, 01:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-09 01:16
Updated : 2026-05-14 18:49
NVD link : CVE-2026-6667
Mitre link : CVE-2026-6667
CVE.ORG link : CVE-2026-6667
JSON object : View
Products Affected
pgbouncer
- pgbouncer
CWE
CWE-862
Missing Authorization
