CVE-2025-46801: Pgpool Global Development Group Pgpool-Ii

Critical severity, CVSS 9.3. EPSS: 0.9% chance of exploitation in the next 30 days.

Pgpool-II provided by PgPool Global Development Group contains an authentication bypass by primary weakness vulnerability. if the vulnerability is exploited, an attacker may be able to log in to the system as an arbitrary user, allowing them to read or tamper with data in the database, and/or disable the database.

Affected products

Published 2025-05-19. Last modified 2026-06-17.