Authentication Bypass Vulnerability in Pgpool-II by PgPool Global Development Group
CVE-2025-46801
9.3CRITICAL
Key Information:
- Status
- Vendor
- CVE Published:
- 19 May 2025
What is CVE-2025-46801?
The Pgpool-II software, developed by the PgPool Global Development Group, contains a vulnerability that allows an attacker to bypass authentication mechanisms. Exploitation of this flaw could enable unauthorized users to access the system as any user, potentially leading to unauthorized reading, manipulation of data, or even disruption of database services. Organizations using Pgpool-II should be aware of this issue and take immediate action to secure their deployments.
Affected Version(s)
Pgpool-II 4.6.0
Pgpool-II 4.5.0 to 4.5.6
Pgpool-II 4.4.0 to 4.4.11
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
CVSS V3.0
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
