Path Traversal Vulnerability in PCP pmproxy Logger Servlet by Red Hat
CVE-2026-16531

5.3MEDIUM

What is CVE-2026-16531?

The PCP pmproxy logger servlet is vulnerable to a path traversal flaw that allows unauthenticated remote attackers to manipulate file and directory paths using specially crafted hostnames. This vulnerability can result in the potential creation of arbitrary files and directories, which may lead to denial of service conditions. Organizations using the affected versions should take immediate action to mitigate risks associated with this security issue.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Francisco Alisson Bezerra (TIM Security Red Team Research, TIM S.p.A), Lucas Gabriel Alves (TIM Security Red Team Research, TIM S.p.A), and Massimiliano Brolli (TIM Security Red Team Research, TIM S.p.A) for reporting this issue.
.