Security Advisory

CVE-2026-16527

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-30 05:30:16
Last updated 2026-07-31 22:41:42
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.