# CVE-2025-46801

## Summary

- **CVE ID:** CVE-2025-46801
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-305
- **Published:** May 19, 2025
- **Last Modified:** Mar 13, 2026

## Description

Pgpool-II provided by PgPool Global Development Group contains an authentication bypass by primary weakness vulnerability. if the vulnerability is exploited, an attacker may be able to log in to the system as an arbitrary user, allowing them to read or tamper with data in the database, and/or disable the database.

## Affected Products

- PgPool Global Development Group — Pgpool-II (4.6.0)
- PgPool Global Development Group — Pgpool-II (4.5.0 to 4.5.6)
- PgPool Global Development Group — Pgpool-II (4.4.0 to 4.4.11)
- PgPool Global Development Group — Pgpool-II (4.3.0 to 4.3.14)
- PgPool Global Development Group — Pgpool-II (4.2.0 to 4.2.21)
- PgPool Global Development Group — Pgpool-II (All versions of 4.1 series)
- PgPool Global Development Group — Pgpool-II (All versions of 4.0 series)

## References

- [CNA](https://www.pgpool.net/mediawiki/index.php/Main_Page#News)
- [CNA](https://jvn.jp/en/jp/JVN06238225/)
- [CVE](https://lists.debian.org/debian-lts-announce/2025/10/msg00014.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.91%
- **EPSS Percentile:** 57.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._