SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-16524

HIGH · CVSS 7.8 EPSS 0.65%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

A command injection vulnerability in the linux_sockets PMDA of PCP allows attackers to exploit improperly validated input from the network.persocket.filter metric, enabling the execution of arbitrary commands as the PMDA user during metric refresh. This high-severity flaw primarily affects Linux systems running PCP, and organizations utilizing this software should prioritize patching to mitigate potential unauthorized command execution risks.

CVE
CVE-2026-16524
Severity
HIGH
CVSS
7.8
EPSS
0.65%
Linux

Original NVD Description

A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.