CVE-2026-16526 Details
Description
A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.
A privilege escalation vulnerability has been identified in the Performance Co-Pilot (PCP) linux_sockets module. This flaw exposes an unsecured internal connection, allowing an attacker with initial code execution to escalate privileges and execute arbitrary commands as root. The vulnerability arises when the linux_sockets PMDA is loaded as a Dynamic Shared Object (DSO) within the PMCD, a configuration that deviates from the default setting. Exploitation can occur locally or remotely, depending on the PMCD and PMProxy configurations.
To mitigate this vulnerability, ensure that the linux_sockets PMDA is not loaded as a DSO within PMCD. The default configuration for this PMDA is daemon mode, which is not affected by this vulnerability. After making changes to the pmcd.conf file, restart the pmcd service for the changes to take effect.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-403 | Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak') | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 21, 2026 | CVE Modified | [email protected] |
| Aug 18, 2026 | CVE Modified | [email protected] |
| Aug 17, 2026 | CVE Modified | [email protected] |
| Aug 4, 2026 | CVE Modified | [email protected] |
| Jul 30, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | New CVE Received | [email protected] |