Junglewise Threat Intelligence

CVE-2026-14459: TUBITAK BILGEM pardus-software argument injection

CVE-2026-14459 · Severity: high · CVSS 8.8 · Published 2026-07-03

Vendors: TUBITAK BILGEM Software Technologies Research Institute.

Executive brief

A security vulnerability has been identified in the Pardus Software management tool, which is used to manage applications on the Pardus operating system. An attacker with local access to the system could exploit this flaw to execute unauthorized commands with elevated privileges. This could lead to a complete compromise of the system, including the theft of sensitive data or disruption of operations.

Technical details

An argument injection vulnerability (CWE-88) exists in TUBITAK BILGEM pardus-software due to improper neutralization of argument delimiters in a command. The flaw resides in versions up to 1.0.4 and is triggered when the application fails to properly sanitize input before passing it to a system command. A local attacker with low privileges can exploit this to inject additional command-line arguments, potentially leading to arbitrary code execution with the privileges of the software (often root or administrative). The issue is resolved in version 1.0.5.

Affected products

  • TUBITAK BILGEM Software Technologies Research Institute pardus-software <= 1.0.4 before 1.0.5

Timeline

  • 2026-07-03: disclosed
  • 2026-07-03: advisory

References

Related threats