Description

An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add data source" feature to break out of the database context and execute shell commands on the underlying operating system.

INFO

Published Date :

2026-04-02T00:00:00.000Z

Last Modified :

2026-04-02T17:39:21.169Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2026-25212 vulnerability.

Vendors Products
Percona
  • Pmm
REFERENCES

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact