PT-2026-66362 · Pcp+1 · Pcp+1

CVE-2026-16524

·

Published

2026-07-30

·

Updated

2026-08-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PCP (affected versions not specified)
Description A command injection flaw exists in the linux sockets PMDA of PCP. The issue occurs due to failed validation of the network.persocket.filter metric, which allows the injection of malicious shell metacharacters via the network. This enables attackers to execute arbitrary commands with the privileges of the PMDA user during metrics refresh.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:55560
ALSA-2026:55617
ALSA-2026:55740
AZL-94377
CVE-2026-16524
OPENSUSE-SU-2026:11490-1
OPENSUSE-SU-2026:21636-1
RHSA-2026:55560
RHSA-2026:55617
RHSA-2026:55740
SUSE-SU-2026:23064-1
SUSE-SU-2026:23174-1
SUSE-SU-2026:23277-1
SUSE-SU-2026:23316-1
SUSE-SU-2026:3505-1
SUSE-SU-2026:3506-1
SUSE-SU-2026:3507-1
SUSE-SU-2026:3508-1

Affected Products

Pcp
Rocky Linux