CVE-2026-92872
Received Received - Intake

Pgpool-II Log Information Disclosure Vulnerability

Vulnerability report for CVE-2026-92872, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: JPCERT/CC

Description

Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Pgpool-II is a middleware that manages PostgreSQL database clusters. This vulnerability involves sensitive information being logged, which could expose cluster details to authenticated attackers.

Detection Guidance

Check Pgpool-II log files for sensitive information leakage. Look for entries containing cluster details or credentials. Use commands like 'grep -r "password" /var/log/pgpool/' or 'tail -n 100 /var/log/pgpool/pgpool.log' to inspect logs.

Impact Analysis

An authenticated attacker could exploit this to gather cluster information, potentially leading to further attacks like data breaches or unauthorized access.

Compliance Impact

This vulnerability may lead to exposure of sensitive cluster information through log files, which could potentially violate data protection requirements under GDPR and HIPAA if such information includes personal or health data.

Mitigation Strategies

Update Pgpool-II to the latest version. Restrict log file permissions to prevent unauthorized access. Disable logging of sensitive data if possible. Review and sanitize existing log files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92872. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart