CVE-2026-6667Disclosure(pgbouncer / pgbouncer)

LOWCVSS 4.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch pgbouncer pgbouncer systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

PgBouncer before 1.25.2 did not perform an appropriate authorization check for the KILL_CLIENT admin command. All users with access to the administration console (which itself requires authorization) could run this command. It would have been correct to allow only users listed in the admin_users parameter.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pgbouncer

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-09); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
pgbouncer

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-05-09: 2Mentions · 2026-05-11: 2Patch / Workaround · 2026-05-09: 1Patch / Workaround · 2026-05-11: 1Technical Details · 2026-05-09: 205-0905-11
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets3 URLs
Full discourse4 posts
  • Euler Taveira@eulerto
    Patch

    PgBouncer 1.25.2 released - Human touch with fresh twist in title race full of uncertainties (including CVE-2026-6664, CVE-2026-6665, Fix CVE-2026-6666, CVE-2026-6667) https://www.pgbouncer.org/changelog.html#pgbouncer-125x

    Post summary

    PgBouncer 1.25.2 release notes include fixes for several CVEs, notably CVE-2026-6666, indicating that patches have been applied.

    0005095
    442 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-6667 📊 Severity: 4.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6667 #CVE-2026-6667 #CVE #Medium #CyberSecurity #InfoSec https://t.co/7B1SttaoWJ

    Post summary

    The text announces the existence of CVE-2026-6667 with basic severity info but provides no technical details, exploits, or mitigation instructions.

    0000028
    157 followersView on X
  • NerdieNews@NewsNerdie
    Patch

    CVE-2026-6667 in PgBouncer: Hackers can terminate client connections using the KILL_CLIENT command without authorization. Versions before 1.25.2 are vulnerable. Patch now to prevent unauthorized access. #NerdieNews #CyberSecurity #InfoSec #Vulnerability https://t.co/iBKtPq3r0U

    Post summary

    CVE-2026-6667 permits unauthenticated users to terminate client connections in PgBouncer via the KILL_CLIENT command on versions before 1.25.2; a patch has been released to mitigate this issue.

    0000038
    59 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6667 Unauthorized KILL_CLIENT Command Execution in PgBouncer Before 1.25.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6667

    Post summary

    The post references CVE-2026-6667, noting an unauthorized KILL_CLIENT command execution in PgBouncer before version 1.25.2, but offers no PoC, exploit code, or mitigation details.

    0000050
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppgbouncerpgbouncer---

Explore more