Improper Certificate Validation in Pgpool-II Affects PostgreSQL Users
CVE-2026-92868

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-92868?

An improper certificate validation vulnerability exists in Pgpool-II, which could enable an unauthenticated attacker to bypass client certificate authentication, potentially compromising the security of PostgreSQL connections. This issue highlights the importance of proper authentication methods to prevent unauthorized access and safeguard sensitive data.

Affected Version(s)

Pgpool-II 4.7.0 <= 4.7.2

Pgpool-II 4.6.0 <= 4.6.7

Pgpool-II 4.5.0 <= 4.5.12

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

CVSS V3.0

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.