CVE-2026-16524
HIGHA command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.
Published: 7/30/2026Modified: 7/30/2026