CVE-2026-6667

EUVD-2026-28879
PgBouncer before 1.25.2 did not perform an appropriate authorization check for the KILL_CLIENT admin command. All users with access to the administration console (which itself requires authorization) could run this command. It would have been correct to allow only users listed in the admin_users parameter.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
Affected Products (NVD)
VendorProductVersion
pgbouncerpgbouncer
𝑥
< 1.25.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pgbouncer
bookworm
no-dsa
bullseye
postponed
bullseye (security)
vulnerable
forky
1.25.2-1
fixed
sid
1.25.2-1
fixed
trixie
1.24.1-1+deb13u2
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
pgbouncer
Azure Linux 3.0
0:1.25.2-1.azl3
fixed