PgBouncer before 1.25.2 did not perform an appropriate authorization check for the KILL_CLIENT admin command. All users with access to the administration console (which itself requires authorization) could run this command. It would have been correct to allow only users listed in the admin_users parameter.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.pgbouncer.org/changelog.html#pgbouncer-125x |
|
History
Sat, 09 May 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pgbouncer
Pgbouncer pgbouncer |
|
| Vendors & Products |
Pgbouncer
Pgbouncer pgbouncer |
Sat, 09 May 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PgBouncer before 1.25.2 did not perform an appropriate authorization check for the KILL_CLIENT admin command. All users with access to the administration console (which itself requires authorization) could run this command. It would have been correct to allow only users listed in the admin_users parameter. | |
| Title | PgBouncer missing authorization check in KILL_CLIENT admin command | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: PostgreSQL
Published:
Updated: 2026-05-09T00:43:53.126Z
Reserved: 2026-04-20T12:25:45.561Z
Link: CVE-2026-6667
No data.
Status : Received
Published: 2026-05-09T01:16:09.287
Modified: 2026-05-09T01:16:09.287
Link: CVE-2026-6667
No data.
OpenCVE Enrichment
Updated: 2026-05-09T03:30:24Z
Weaknesses