CVE-2026-25212
An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add data source" feature to break out of the database context and execute shell commands on the underlying operating system.
- Affected products
- Percona Pmm
- Percona Monitoring And Management
- < 3.7.0
- Fix
- Available
- CVSS 3.1
- 9.9 CRITICAL
- EPSS
- 0.3% (21th percentile)
- Weakness
- CWE-250
- NVD status
- Analyzed
- Published
- 2026-04-02
CVE-2026-25212 at NVD
2 known exploits for CVE-2026-25212
Proof-of-concept code and exploit modules indexed by Sploitus