Executive brief
A security vulnerability has been identified in the Pardus Software management tool used in the Pardus operating system. An attacker with low-level access to a computer could exploit this flaw to bypass security checks and execute unauthorized commands with elevated privileges. This could lead to a full system takeover, unauthorized data access, or disruption of services on the affected machine.
Technical details
A missing authorization vulnerability (CWE-862) exists in the pardus-software component of the Pardus operating system. The flaw allows a local attacker to perform argument injection due to insufficient validation and authorization checks when handling software management tasks. By exploiting this, a low-privileged user can execute arbitrary commands with the privileges of the software manager, typically root. The issue affects versions up to and including 1.0.4 and is addressed in version 1.0.5.
Affected products
- TUBITAK BILGEM Software Technologies Research Institute pardus-software <= 1.0.4 before 1.0.5
Timeline
- 2026-07-03: advisory: CVE published by TR-CERT and NVD
- 2026-07-03: patched: Fixed in version 1.0.5