CVE-2025-26701
An issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can lead to SSH access, use of Sudo to root, and sensitive data exposure. This is fixed in PMM2 2.42.0-1.ova, 2.43.0-1.ova, 2.43.1-1.ova, 2.43.2-1.ova, and 2.44.0-1.ova and in PMM3 3.0.0-1.ova and later.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.44%
- CWE
- CWE-1393
- Published
- 2025-03-11
- Last modified
- 2026-03-13
Affected products
- Percona Monitoring and Management
- Percona Monitoring and Management
- Percona Monitoring and Management
- Percona Monitoring and Management
- Percona Monitoring and Management
- Percona Monitoring and Management
Weakness type
Related vulnerabilities
- CVE-2026-69657 — XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the...
- CVE-2026-82698 — sambitraj Student-Management-System aca.sql default password
- CVE-2026-19851 — Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5
- CVE-2026-5269 — Navigator NCS and MCP System Accounts with Default Passwords
- CVE-2026-54445 — Vantage6: Set admin user and password from environment or configuration
- CVE-2026-35075 — Hardcoded default Password for Service Account
- CVE-2026-8672 — Default credentials for internal DB
- CVE-2026-33784 — JSI Virtual Lightweight Collector: Default password is not required to be changed which allows unauthorized high-privileged access