Junglewise Threat Intelligence

CVE-2026-16531: Red Hat PCP path traversal in pmproxy logger servlet

CVE-2026-16531 · Severity: medium · CVSS 5.3 · Published 2026-07-30

Vendors: Red Hat.

Executive brief

Performance Co-Pilot (PCP), a system performance monitoring toolkit, contains a flaw in its pmproxy component. An unauthenticated remote attacker can exploit this to create files and directories in unauthorized locations on the server. This could lead to a denial of service by filling up disk space or disrupting system operations, potentially impacting the availability of monitoring services and the underlying host.

Technical details

A path traversal vulnerability (CWE-22) exists in the pmproxy logger servlet within Performance Co-Pilot (PCP). The servlet (specifically the POST /logger/label endpoint) accepts a binary __pmLogLabel PDU and uses the provided hostname field to construct archive file paths without proper sanitization. By supplying a crafted hostname containing directory traversal sequences (e.g., '../../..'), an unauthenticated attacker can force pmproxy to create files and directory trees at arbitrary paths accessible to the pcp process user. The logger servlet is registered unconditionally and is active regardless of the pmproxy configuration, requiring only network reachability on TCP port 44322.

Affected products

  • Red Hat Performance Co-Pilot (PCP) Red Hat Enterprise Linux 8, 9, 10; OpenShift Container Platform 4

Timeline

  • 2026-07-22: disclosed: Initial report in Red Hat Bugzilla
  • 2026-07-30: advisory: NVD publication date

References