CVE-2026-92872
Description
A flaw was found in Pgpool-II. The application writes sensitive cluster details directly into log files. An authenticated attacker can exploit this issue to view database cluster information, resulting in unauthorized information disclosure.
Statement
Red Hat rates this vulnerability as Moderate severity because exploitation requires valid authentication and impact is restricted to read-only cluster details without enabling data tampering or service interruption. Furthermore, the pgpool-II component is not included or supported in Red Hat Enterprise Linux releases and is only distributed through community projects such as Fedora.
Mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Understanding the Weakness (CWE)
Confidentiality
Technical Impact: Read Files or Directories
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.