CVE-2026-16527
Red Hat Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7
An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.
- CVSS
- 7.3
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.07.30