CVE-2026-25212 affects Percona PMM versions before 3.7. The vulnerability exists because an internal database user retains superuser privileges that are not necessary for the intended operation. An attacker with pmm-admin privileges can abuse the "Add data source" functionality to escape the intended database context and execute shell commands on the underlying operating system. In effect, a privileged application user can pivot through the internal data source mechanism into OS-level command execution on the PMM host.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, standalone Python proof-of-concept for CVE-2026-25212 affecting Percona PMM versions earlier than 3.7. The repo contains only two files: a README describing the vulnerability, prerequisites, and usage, and a single executable script, poc.py, which is the exploit entry point. The exploit workflow is straightforward and operational: it accepts a target base URL, a grafana_session cookie, and an arbitrary command. It disables TLS verification, authenticates by setting the supplied Grafana session cookie, then creates a PostgreSQL data source through the PMM/Grafana API at /graph/api/datasources. That data source points to localhost:5432 with database postgres and user postgres. After obtaining the returned datasource UID, the script sends SQL to /graph/api/ds/query. Its core capability is authenticated remote code execution. It abuses PostgreSQL's COPY ... TO PROGRAM feature, relying on the vulnerable condition that the internal PostgreSQL user retains SUPERUSER privileges. The script executes the supplied OS command, redirects output to a randomly named file in /tmp, creates a temporary SQL table, imports the file contents with COPY FROM, and prints the returned lines to the operator. Finally, it attempts cleanup by deleting the created data source and removing the temporary file via another COPY ... TO PROGRAM invocation. There is no exploit framework involved, no shell staging, and no persistence logic. The payload is a basic hardcoded command-execution chain, making this best classified as OPERATIONAL rather than weaponized. The main fingerprintable targets are the PMM/Grafana API paths, the internal PostgreSQL endpoint localhost:5432, the grafana_session cookie requirement, and the temporary file path under /tmp used for command output capture.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.