Fedora Account System
Red Hat Associate
Red Hat Customer
Summary: The pmproxy REST API exposes a /store endpoint writing to any PMDA metric via pmStore() without authentication. Two authentication flags (-S for credential requirements, -Q for client certificate) exist as case blocks in the source but are absent from the short_options string and longopts table, making both code paths permanently dead and impossible to activate. Combined with an unrestricted hostspec parameter, an unauthenticated HTTP attacker can force pmproxy to connect to pmcd via Unix socket, bypassing all pmcd [access] host rules that cover only IPv4 and IPv6 transports. Prerequisites: pmproxy running and reachable on default port 44322. pmcd running. linux_sockets PMDA loaded (required for the full RCE chain with Vulnerability 3).
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:55560 https://access.redhat.com/errata/RHSA-2026:55560
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:55740 https://access.redhat.com/errata/RHSA-2026:55740
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:55617 https://access.redhat.com/errata/RHSA-2026:55617