CVE-2026-16527

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.

  • Published Jul 30, 2026
  • CVSS 7.3 high
  • 0.6% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

In the news

CVE-2026-16527 at the National Vulnerability Database