{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-16526/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-16526"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Performance Co-Pilot (PCP)","Red Hat Enterprise Linux 7","Red Hat Enterprise Linux 8","Red Hat Enterprise Linux 9","Red Hat Enterprise Linux 10","Red Hat OpenShift Container Platform 4","Red Hat Enterprise Linux","Red Hat OpenShift Container Platform","Red Hat Enterprise Linux 6"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","linux","cve-2026-16526","remote-code-execution","cve-2026-16527","monitoring-tool","denial-of-service","vulnerability","pcp"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eA security vulnerability identified as CVE-2026-16526 exists within the Performance Co-Pilot (PCP) linux_sockets module, specifically categorized as CWE-403: Exposure of File Descriptor to Unintended Control Sphere. This vulnerability stems from an insecure internal connection that leaks file descriptors. An attacker who has already obtained initial low-privilege code execution on a target system can exploit this leak to interact with privileged internal PCP processes. By successfully abusing this communication channel, an unprivileged user can escalate their permissions to root, allowing for the execution of arbitrary commands with full system control. The vulnerability affects multiple versions of Red Hat Enterprise Linux and Red Hat OpenShift Container Platform utilizing the PCP package.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in full local privilege escalation. In environments where PCP is deployed, this poses a high risk to system integrity, as attackers can bypass standard access controls to execute unauthorized code as the root user. This could lead to data exfiltration, backdooring of the host, or total system compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eIdentify all systems running the affected 'pcp' package across the environment using your asset inventory or package management logs.\u003c/li\u003e\n\u003cli\u003eApply security updates provided by Red Hat to resolve CVE-2026-16526 as documented in the Red Hat Security Advisory.\u003c/li\u003e\n\u003cli\u003eUntil patching is complete, restrict access to the PCP monitoring services to authorized administrative users only.\u003c/li\u003e\n\u003cli\u003eEnsure that auditd or system-level process monitoring is configured to detect unexpected privilege changes or suspicious activities originating from the 'pcp' service user context.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-07-30T07:20:27Z","date_published":"2026-07-30T07:20:10Z","id":"https://feed.craftedsignal.io/briefs/2026-07-pcp-privesc/","summary":"A file descriptor leak in the Performance Co-Pilot (PCP) linux_sockets module allows an attacker with initial code execution to escalate privileges to root.","title":"Privilege Escalation Vulnerability in Performance Co-Pilot linux_sockets Module","url":"https://feed.craftedsignal.io/briefs/2026-07-pcp-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-16526","version":"https://jsonfeed.org/version/1.1"}