Executive brief
Percona Monitoring and Management (PMM) is a platform used to monitor and manage the performance of open-source databases. A security vulnerability exists where an internal database user has excessive permissions, allowing an authorized user with administrative rights to escape the database environment. This could allow an attacker to execute arbitrary commands on the underlying server, potentially leading to a full system takeover and unauthorized access to sensitive database monitoring data.
Technical details
A vulnerability classified as 'Execution with Unnecessary Privileges' (CWE-250) exists in Percona PMM before version 3.7.0. The root cause is an internal database user retaining specific superuser privileges that should have been restricted. An attacker with 'pmm-admin' credentials can exploit the 'Add data source' feature to escape the database context. This breakout allows for the execution of arbitrary shell commands on the underlying operating system with the privileges of the PMM service. The vulnerability is reachable over the network and requires low-level administrative authentication, but results in a high impact on confidentiality, integrity, and availability (Scope Changed). The issue is resolved in PMM version 3.7.0.
Affected products
- Percona Percona Monitoring and Management (PMM) versions before 3.7.0
Timeline
- 2026-04-01: patched: PMM 3.7.0 released fixing the issue.
- 2026-04-02: disclosed: CVE-2026-25212 published.