CVE-2026-16527 - Pcp: pcp pmproxy: unauthenticated access to /store endpoint allows bypassing pmcd access rules
CVE ID :CVE-2026-16527
Published : July 30, 2026, 6:25 a.m. | 27 minutes ago
Description :An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : July 30, 2026, 6:25 a.m. | 27 minutes ago
Description :An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...