PT-2026-29794 · Percona · Percona Pmm
Published
2026-04-02
·
Updated
2026-04-03
·
CVE-2026-25212
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Percona PMM versions prior to 3.7
Description
A flaw exists in Percona PMM that allows an attacker with pmm-admin rights to execute shell commands on the underlying operating system. This is possible because an internal database user retains specific superuser privileges, which can be exploited through the 'Add data source' feature to break out of the database context.
Recommendations
Update Percona PMM to version 3.7 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Percona Pmm