Description
An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code execution.
Published: 2026-09-30
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution via out-of-bounds write
Action: Immediate Patch
AI Analysis

Impact

An out-of-bounds write condition exists in Pgpool-II that may lead to abnormal process termination or arbitrary code execution by an authenticated user. The vulnerability stems from insufficient bounds checking during data handling, which can corrupt memory and allow attackers to execute arbitrary instructions. This flaw can compromise confidentiality, integrity and availability of the database cluster if exploited.

Affected Systems

Pgpool Global Development Group’s Pgpool-II product is affected. The specific product version range responsible for the flaw was not disclosed in the advisory. Administrators should verify the installed version and compare it against the vendor’s documentation for affected releases. The vulnerability requires authentication within the Pgpool-II service to be triggered.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity. No EPSS score was provided, so the current prevalence of exploitation is uncertain. The flaw is not present in the CISA KEV catalog, yet the high impact and requirement for authenticated access suggest that privileged users could exploit it if proper controls are not in place. Attackers would need legitimate credentials to initiate the vulnerable operation, making internal threat actors or compromised accounts primary vectors.

Generated by OpenCVE AI on September 30, 2026 at 12:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest Pgpool-II release that contains the out-of-bounds write fix
  • Restrict authentication to trusted users and employ least-privilege database roles
  • Implement network segmentation to limit exposure of the Pgpool-II service and monitor logs for abnormal crashes

Generated by OpenCVE AI on September 30, 2026 at 12:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write Vulnerability Allowing Code Execution in Pgpool-II

Wed, 30 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code execution.
Weaknesses CWE-787
References
Metrics cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-30T07:20:27.931Z

Reserved: 2026-09-17T06:31:54.744Z

Link: CVE-2026-92867

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T08:16:34.557

Modified: 2026-09-30T08:16:34.557

Link: CVE-2026-92867

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T12:15:17Z

Weaknesses