Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 21 Apr 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Percona monitoring And Management
|
|
| CPEs | cpe:2.3:a:percona:monitoring_and_management:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Percona monitoring And Management
|
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Internal superuser privileges enable remote code execution in Percona PMM 3.6.x | |
| First Time appeared |
Percona
Percona pmm |
|
| Vendors & Products |
Percona
Percona pmm |
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add data source" feature to break out of the database context and execute shell commands on the underlying operating system. | |
| Weaknesses | CWE-250 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-02T17:39:21.169Z
Reserved: 2026-01-30T00:00:00.000Z
Link: CVE-2026-25212
Updated: 2026-04-02T17:37:50.318Z
Status : Analyzed
Published: 2026-04-02T17:16:21.687
Modified: 2026-04-21T00:33:36.707
Link: CVE-2026-25212
No data.
OpenCVE Enrichment
Updated: 2026-04-03T09:19:03Z