CVE-2026-16526CWE-403

CVE-2026-16526

High · published July 30, 2026

CVSS v3.1
8.8
EPSS
0%
Percentile
37.9
In the wild
Unconfirmed
What it is

A flaw in the PCP linux_sockets module exposes an unsecured internal connection.

An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00454 · 37.9th percentile
Weakness
CWE-403 · Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak')
Published
2026-07-30T10:25Z
References (5)
EPSS history
Timeline
  • 30 JUL 05:20Z
    Pcp: pcp: privilege escalation to root via linux_sockets pmda vulnerability
    cvelistv5