Description
An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificate authentication.
Published: 2026-09-30
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass (client certificate validation flaw)
Action: Patch Now
AI Analysis

Impact

The vulnerability is an improper certificate validation flaw in Pgpool-II that allows an unauthenticated attacker to bypass client certificate authentication, which can lead to unauthorized access to the backend database services. The weakness is identified as CWE-295. Attackers would be able to connect to Pgpool-II using arbitrary certificates or without any authentication, depending on server configuration. The impact is a loss of authentication integrity, potentially enabling data theft or manipulation.

Affected Systems

Affected systems are those running Pgpool-II from the Pgpool Global Development Group. No specific version numbers are disclosed, so all deployments of Pgpool-II should be examined for the presence of this issue. The product must be checked for manufacturer guidance on mitigation.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate risk, and the EPSS score is not available, suggesting limited publicly known exploit data. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely remote network access; an attacker can reach the Pgpool-II service over the network and perform the bypass without needing any existing credentials. Organizations should assume the flaw could be used to gain full database access where Pgpool-II is configured to forward requests.

Generated by OpenCVE AI on September 30, 2026 at 12:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security patch from the Pgpool Global Development Group that corrects the certificate validation logic.
  • If a patch is not available, restrict network access to Pgpool-II so only trusted hosts can reach it, and consider using firewall rules or VPN tunnels.
  • Configure Pgpool-II to enforce strict client certificate validation, disallow self-signed or untrusted certificates, and require mutual TLS authentication.
  • Periodically scan logs for unauthorized connection attempts and monitor database activity for signs of exploitation.

Generated by OpenCVE AI on September 30, 2026 at 12:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Title Pgpool-II Client Certificate Validation Vulnerability

Wed, 30 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificate authentication.
Weaknesses CWE-295
References
Metrics cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-30T07:20:48.300Z

Reserved: 2026-09-17T06:31:54.744Z

Link: CVE-2026-92868

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T08:16:34.723

Modified: 2026-09-30T08:16:34.723

Link: CVE-2026-92868

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T12:15:17Z

Weaknesses
  • CWE-295

    Improper Certificate Validation