Vulnerability Description
A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://access.redhat.com/security/cve/CVE-2026-16524
- https://bugzilla.redhat.com/show_bug.cgi?id=2506023
FAQ
What is CVE-2026-16524?
CVE-2026-16524 is a vulnerability with a CVSS score of 7.8 (HIGH). A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as ...
How severe is CVE-2026-16524?
CVE-2026-16524 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-16524?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.