PT-2026-39229 · Pgbouncer+1 · Pgbouncer+1

·

CVE-2026-6667

·

Published

2026-05-08

·

Updated

2026-07-14

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions PgBouncer versions prior to 1.25.2
Description An improper authorization check exists for the 'KILL CLIENT' admin command. Any user with access to the administration console can execute this command, whereas it should be restricted exclusively to users defined in the admin users parameter.
Recommendations Update to version 1.25.2 or later.

Fix

DoS

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-86240
BDU:2026-06727
BIT-PGBOUNCER-2026-6667
CLEANSTART-2026-DL78780
CVE-2026-6667

Affected Products

Pgbouncer
Red Os