CVE-2026-16526
A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.45%
- CWE
- CWE-403
- Published
- 2026-07-30
- Last modified
- 2026-08-21
Affected products
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 9
Weakness type
Related vulnerabilities
- CVE-2026-33263 — When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with...
- CVE-2026-40042 — Pachno 1.0.6 Wiki TextParser XML External Entity Injection
- CVE-2025-15114 — Ksenia Security lares Home Automation 1.6 PIN Exposure Vulnerability
- CVE-2024-58280 — CMSimple 5.15 Remote Command Execution via Extensions Configuration
- CVE-2024-21626 — runc container breakout through process.cwd trickery and leaked fds