Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-16527

Опубликовано: 30 июл. 2026
Источник: debian

Описание

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pcpunfixedpackage
pcpno-dsatrixiepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2506031

Связанные уязвимости

CVSS3: 7.3
ubuntu
19 дней назад

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.

CVSS3: 7.3
redhat
19 дней назад

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.

CVSS3: 7.3
nvd
19 дней назад

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.

CVSS3: 7.3
github
19 дней назад

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.

suse-cvrf
12 дней назад

Security update for pcp