← Back

Monitoring And Management

monitoring_and_management

Vendor: Percona • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Percona
1Monitoring And Management
Jul 24, 2026
Apr 2, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add data source" feature to break out of the da...Show more
An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add data source" feature to break out of the database context and execute shell commands on the underlying operating system.Show less
1Percona
1Monitoring And Management
Jun 17, 2026
Jun 6, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalize and sanitize URL paths to reject path traversal attempts. This allows an unauth...Show more
In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalize and sanitize URL paths to reject path traversal attempts. This allows an unauthenticated remote user, when a crafted POST request is made against unauthenticated API routes, to access otherwise protected API routes leading to escalation of privileges and information disclosure.Show less
1Percona
1Monitoring And Management
Jun 17, 2026
Feb 6, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
pmm-server in Percona Monitoring and Management (PMM) 2.2.x before 2.2.1 allows unauthenticated denial of service.