An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add data source" feature to break out of the database context and execute shell commands on the underlying operating system.
An internal database user in PMM possesses excessive superuser privileges. An attacker with pmm-admin rights can exploit the 'Add data source' feature (adding a data source) to abuse these privileges. Through a specially crafted request, it is possible to escape the isolated database context and execute system commands (RCE) at the operating system level.
An attacker can execute arbitrary shell commands on the server hosting Percona PMM, leading to full system compromise — including access to sensitive data, configuration modification, and potential lateral movement within the network.
Percona PMM should be updated to version 3.7.0 or later, in which the described vulnerability has been removed. Patch details are available in the official release notes at the address indicated in the vendor references.
Percona Monitoring and Management (PMM) in versions prior to 3.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HPercona Monitoring And Management
APPPercona< 3.7.0
Related vulnerabilities
Path traversal w Percona PMM umożliwia pominięcie uwierzytelniania
pmm-server in Percona Monitoring and Management (PMM) 2.2.x before 2.2.1 allows unauthenticated denial of serv...
Command injection w MariaDB mysql-wsrep via wsrep_sst_method
Pominięcie uwierzytelnienia LDAP w Percona Server przez puste hasło
Percona Server resetuje hasło root do pustej wartości podczas aktualizacji