PgBouncer before 1.25.2 did not perform an appropriate authorization check for the KILL_CLIENT admin command. All users with access to the administration console (which itself requires authorization) could run this command. It would have been correct to allow only users listed in the admin_users parameter.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.pgbouncer.org/changelog.html#pgbouncer-125x |
|
History
Sat, 09 May 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pgbouncer
Pgbouncer pgbouncer |
|
| Vendors & Products |
Pgbouncer
Pgbouncer pgbouncer |
Sat, 09 May 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PgBouncer before 1.25.2 did not perform an appropriate authorization check for the KILL_CLIENT admin command. All users with access to the administration console (which itself requires authorization) could run this command. It would have been correct to allow only users listed in the admin_users parameter. | |
| Title | PgBouncer missing authorization check in KILL_CLIENT admin command | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: PostgreSQL
Published:
Updated: 2026-05-09T00:43:53.126Z
Reserved: 2026-04-20T12:25:45.561Z
Link: CVE-2026-6667
No data.
Status : Received
Published: 2026-05-09T01:16:09.287
Modified: 2026-05-09T01:16:09.287
Link: CVE-2026-6667
No data.
OpenCVE Enrichment
Updated: 2026-05-09T03:30:24Z