CVE-2026-25212

CRITICAL

Percona PMM <3.7 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-25212. PoCs published by 5170Temp.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-25212, demonstrating an authenticated RCE vulnerability in Percona PMM < 3.7. The exploit abuses PostgreSQL's 'COPY ... TO PROGRAM' feature via a crafted datasource to execute arbitrary commands.

Description

An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add data source" feature to break out of the database context and execute shell commands on the underlying operating system.

Exploits (1)

github WORKING POC 1 stars
by 5170Temp · pythonpoc
https://github.com/5170Temp/CVE-2026-25212

This repository contains a functional exploit for CVE-2026-25212, demonstrating an authenticated RCE vulnerability in Percona PMM < 3.7. The exploit abuses PostgreSQL's 'COPY ... TO PROGRAM' feature via a crafted datasource to execute arbitrary commands.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Percona PMM < 3.7
Auth required
Prerequisites: Authenticated session with 'pmm-admin' rights · Valid 'grafana_session' cookie
mistral-large-3 · analyzed Jun 20, 2026 Full analysis →

Scores

CVSS v3 9.9
EPSS 0.0029
EPSS Percentile 21.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-250
Status published
Products (1)
percona/monitoring_and_management < 3.7.0
Published Apr 02, 2026
Tracked Since Apr 02, 2026