Improper Certificate Validation in Pgpool-II Affects PostgreSQL Users
CVE-2026-92868
6.9MEDIUM
Key Information:
- Status
- Vendor
- CVE Published:
- 30 September 2026
What is CVE-2026-92868?
An improper certificate validation vulnerability exists in Pgpool-II, which could enable an unauthenticated attacker to bypass client certificate authentication, potentially compromising the security of PostgreSQL connections. This issue highlights the importance of proper authentication methods to prevent unauthorized access and safeguard sensitive data.
Affected Version(s)
Pgpool-II 4.7.0 <= 4.7.2
Pgpool-II 4.6.0 <= 4.6.7
Pgpool-II 4.5.0 <= 4.5.12
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
CVSS V3.0
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
