10

CVE-2025-26701

An issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can lead to SSH access, use of Sudo to root, and sensitive data exposure. This is fixed in PMM2 2.42.0-1.ova, 2.43.0-1.ova, 2.43.1-1.ova, 2.43.2-1.ova, and 2.44.0-1.ova and in PMM3 3.0.0-1.ova and later.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorPercona
Product Monitoring and Management
Default Statusunknown
Version < 2.42.0-1.ova
Version 2.38
Status affected
Version < 2.43.0-1.ova
Version 2.43.0
Status affected
Version < 2.43.1-1.ova
Version 2.43.1
Status affected
Version < 2.43.2-1.ova
Version 2.43.2
Status affected
Version < 2.44.0-1.ova
Version 2.44.0
Status affected
Version < 3.0.0-1.ova
Version 3.0.0
Status affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.09% 0.27
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
cve@mitre.org 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-1393 Use of Default Password

The product uses default passwords for potentially critical functionality.