CVE-2025-46801
Published: May 19, 2025
Modified: Nov 3, 2025
CVSS v3.0
9.8
Description
Pgpool-II provided by PgPool Global Development Group contains an authentication bypass by primary weakness vulnerability. if the vulnerability is exploited, an attacker may be able to log in to the system as an arbitrary user, allowing them to read or tamper with data in the database, and/or disable the database.
| Vendor | Product | Versions |
|---|---|---|
PgPool Global Development Group | Pgpool-II | affected 4.6.0 |
PgPool Global Development Group | Pgpool-II | affected 4.5.0 to 4.5.6 |
PgPool Global Development Group | Pgpool-II | affected 4.4.0 to 4.4.11 |
PgPool Global Development Group | Pgpool-II | affected 4.3.0 to 4.3.14 |
PgPool Global Development Group | Pgpool-II | affected 4.2.0 to 4.2.21 |
PgPool Global Development Group | Pgpool-II | affected All versions of 4.1 series |
PgPool Global Development Group | Pgpool-II | affected All versions of 4.0 series |
Weaknesses (CWE)
CVSS v3.0 Details
CVSS v3.0 Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now