OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-92873

HIGH · CVSS 7.3 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

Pgpool-II is vulnerable due to a flawed authentication algorithm that permits unauthenticated attackers to elevate an arbitrary watchdog node to the leader node. This could lead to unauthorized control over the Pgpool-II cluster, potentially compromising the integrity and availability of the database management system. Organizations utilizing Pgpool-II should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-92873
Severity
HIGH
CVSS
7.3
EPSS
0.31%

Original NVD Description

Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node.