Home

Description

PgBouncer before 1.25.2 did not perform an appropriate authorization check for the KILL_CLIENT admin command. All users with access to the administration console (which itself requires authorization) could run this command. It would have been correct to allow only users listed in the admin_users parameter.

PUBLISHED Reserved 2026-04-20 | Published 2026-05-09 | Updated 2026-05-09 | Assigner PostgreSQL




MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Problem types

Missing Authorization

Credits

Thanks to HarutoKimura for finding and reporting this problem. finder

References

www.pgbouncer.org/changelog.html

cve.org (CVE-2026-6667)

nvd.nist.gov (CVE-2026-6667)

Download JSON