Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-16527

Опубликовано: 30 июл. 2026
Источник: redhat
CVSS3: 7.3

Описание

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.

Отчет

This is an Important flaw in Performance Co-Pilot (PCP) pmproxy that allows an unauthenticated remote attacker to bypass pmcd access controls. By sending crafted requests to the /store endpoint, an attacker can write to any Performance Metrics Domain Agent (PMDA) metric, potentially leading to arbitrary code execution if pmproxy is running and reachable on its default port.

Меры по смягчению последствий

To mitigate this issue, restrict network access to the pmproxy service (port 44322/TCP) to trusted hosts only using firewall rules. If pmproxy functionality is not required, disable the service. Disabling the service will prevent remote access to performance metrics via pmproxy. To disable the service, run: sudo systemctl stop pmproxy and sudo systemctl disable pmproxy. If firewalling, ensure to reload the firewall rules after making changes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10pcpAffected
Red Hat Enterprise Linux 6pcpOut of support scope
Red Hat Enterprise Linux 7pcpAffected
Red Hat Enterprise Linux 8pcpAffected
Red Hat Enterprise Linux 9pcpAffected
Red Hat OpenShift Container Platform 4rhcosNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-306
https://bugzilla.redhat.com/show_bug.cgi?id=2506031PCP: PCP pmproxy: Unauthenticated access to /store endpoint allows bypassing pmcd access rules

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
19 дней назад

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.

CVSS3: 7.3
nvd
19 дней назад

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.

CVSS3: 7.3
debian
19 дней назад

An unauthenticated remote attacker can bypass access controls by sendi ...

CVSS3: 7.3
github
19 дней назад

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.

suse-cvrf
12 дней назад

Security update for pcp

7.3 High

CVSS3