Path Traversal Vulnerability in PCP pmproxy Logger Servlet by Red Hat
CVE-2026-16531
5.3MEDIUM
What is CVE-2026-16531?
The PCP pmproxy logger servlet is vulnerable to a path traversal flaw that allows unauthenticated remote attackers to manipulate file and directory paths using specially crafted hostnames. This vulnerability can result in the potential creation of arbitrary files and directories, which may lead to denial of service conditions. Organizations using the affected versions should take immediate action to mitigate risks associated with this security issue.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Francisco Alisson Bezerra (TIM Security Red Team Research, TIM S.p.A), Lucas Gabriel Alves (TIM Security Red Team Research, TIM S.p.A), and Massimiliano Brolli (TIM Security Red Team Research, TIM S.p.A) for reporting this issue.