{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/pcp/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-16524"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["pcp","Red Hat Enterprise Linux 10","Red Hat Enterprise Linux 7","Red Hat Enterprise Linux 8","Red Hat Enterprise Linux 9","Red Hat OpenShift Container Platform 4"],"_cs_severities":["high"],"_cs_tags":["vulnerability","command-injection","pcp","linux"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003ePerformance Co-Pilot (PCP) contains a critical command injection vulnerability identified as CVE-2026-16524. The flaw resides within the linux_sockets Performance Metrics Domain Agent (PMDA). Specifically, the PMDA fails to properly validate input provided via the 'network.persocket.filter' metric. A local attacker with low-level privileges can craft malicious shell metacharacters and inject them into this metric. When the PCP agent refreshes its metrics, the underlying system executes these injected characters as commands with the privileges of the PMDA user. This vulnerability impacts multiple versions of Red Hat Enterprise Linux (RHEL 7 through 10) and OpenShift Container Platform, posing a significant risk for privilege escalation and unauthorized system activity on monitored hosts. Defenders must prioritize patching the 'pcp' package to mitigate this vector.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains initial access to the target host with low-privileged user rights.\u003c/li\u003e\n\u003cli\u003eAttacker identifies that the PCP 'linux_sockets' PMDA is active and accepting metric configuration updates.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious string containing shell metacharacters (e.g., ;, \u0026amp;\u0026amp;, |).\u003c/li\u003e\n\u003cli\u003eAttacker writes this malicious string to the 'network.persocket.filter' metric configuration.\u003c/li\u003e\n\u003cli\u003eThe PCP 'linux_sockets' PMDA process triggers a refresh of the metrics configuration.\u003c/li\u003e\n\u003cli\u003eThe PMDA process parses the tainted 'network.persocket.filter' input without sanitization.\u003c/li\u003e\n\u003cli\u003eThe system executes the embedded shell commands under the context of the PMDA service user.\u003c/li\u003e\n\u003cli\u003eAttacker achieves arbitrary command execution for further post-exploitation activities.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-16524 allows an attacker to execute arbitrary commands on the affected system. Given that performance monitoring agents often run with specific service-level privileges, this can lead to full system compromise, exfiltration of sensitive monitoring data, or lateral movement within the environment. RHEL 7, 8, 9, and 10, along with OpenShift environments, are affected by this vulnerability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the 'pcp' package to the latest version provided by Red Hat to patch CVE-2026-16524.\u003c/li\u003e\n\u003cli\u003eRestrict write access to performance metric configuration files and directories to authorized administrative accounts only.\u003c/li\u003e\n\u003cli\u003eMonitor for abnormal process execution spawned by PCP-related binaries, such as 'pmda' processes, using auditd or EDR telemetry.\u003c/li\u003e\n\u003cli\u003eAudit existing 'network.persocket.filter' configurations for anomalous characters or suspicious commands.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-30T07:20:04Z","date_published":"2026-07-30T07:20:04Z","id":"https://feed.craftedsignal.io/briefs/2026-07-pcp-command-injection/","summary":"A command injection vulnerability (CVE-2026-16524) in the PCP linux_sockets PMDA allows local attackers to execute arbitrary commands by injecting shell metacharacters into the network.persocket.filter metric.","title":"Command Injection in PCP linux_sockets PMDA","url":"https://feed.craftedsignal.io/briefs/2026-07-pcp-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Pcp","version":"https://jsonfeed.org/version/1.1"}