Red HatCVE-2026-16527
Red Hat Enterprise Linux 6: remote code execution
High7.3CVE-2026-16527 · Published Jul 30, 2026 · updated Aug 21, 2026
An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Enterprise Linux 6 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 7 Product | all versions | No fix yet |
| Red Hat OpenShift Container Platform 4 Product | all versions | No fix yet |
Details and references
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 30 | ansible-collection-redhat-leapp: information disclosure | Medium6.2 | No fix yet |
| Jul 30 | ansible-collection-redhat-leapp.: insecure permissions | Medium5.5 | No fix yet |
| Jul 30 | Red Hat Samba: out-of-bounds read | Medium5.3 | No fix yet |
| Jul 30 | Red Hat Enterprise Linux 10: improper authorization | High8.8 | No fix yet |
| Jul 30 | Red Hat Samba: denial of service | Medium5.3 | No fix yet |
| Jul 30 | Red Hat Cost Management Metrics Operator: server-side request forgery | High7.6 | No fix yet |