[ClusterLabs] PCS hotfix releases for CVE-2026-84828

Michal Pospíšil mpospisi at redhat.com
Thu Sep 10 12:34:01 UTC 2026


I would like to announce hotfix releases of PCS, versions:
- 0.12.3.1,
- 0.11.12.2,
- 0.10.20.

Source code is available at:
https://github.com/ClusterLabs/pcs/archive/refs/tags/v0.12.3.1.tar.gz
https://github.com/ClusterLabs/pcs/archive/refs/tags/v0.11.12.2.tar.gz
https://github.com/ClusterLabs/pcs/archive/refs/tags/v0.10.20.tar.gz
or
https://github.com/ClusterLabs/pcs/archive/refs/tags/v0.12.3.1.zip
https://github.com/ClusterLabs/pcs/archive/refs/tags/v0.11.12.2.zip
https://github.com/ClusterLabs/pcs/archive/refs/tags/v0.10.20.zip

These releases fix a security vulnerability in the `pcs host auth`
command, which could previously be exploited by non-root users to
read arbitrary files on the filesystem.

The vulnerability was discovered by Peter Romančík and it was filed
as CVE-2026-84828 [1] with a CVSSv3.1 score of 6.5.


Stay safe and update,
Michal

[1] https://www.cve.org/CVERecord?id=CVE-2026-84828



More information about the Users mailing list