Back to overview

CVE-2025-26701

CRITICAL
10.0
CVSS 3.1
Description
An issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can lead to SSH access, use of Sudo to root, and sensitive data exposure. This is fixed in PMM2 2.42.0-1.ova, 2.43.0-1.ova, 2.43.1-1.ova, 2.43.2-1.ova, and 2.44.0-1.ova and in PMM3 3.0.0-1.ova and later.

Metadata

CVE ID
CVE-2025-26701
State
PUBLISHED
Assigner
mitre
Reserved
2025-02-14 00:00 UTC
Published
2025-03-11 00:00 UTC
Last updated
2025-03-11 19:27 UTC
Primary CWE
CWE-1393
CWE-1393 Use of Default Password
Vendor / Product
Percona / Monitoring and Management
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Percona Monitoring and Management 2.38 < 2.42.0-1.ova, 2.43.0 < 2.43.0-1.ova, 2.43.1 < 2.43.1-1.ova, 2.43.2 < 2.43.2-1.ova …
Weakness (CWE)
CWESourceDescription
CWE-1393 cna CWE-1393 Use of Default Password
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview