Junglewise Threat Intelligence

CVE-2026-16287: TUBITAK BILGEM pardus-update OS command injection

CVE-2026-16287 · Severity: high · CVSS 7.8 · Published 2026-07-23

Vendors: TUBITAK BILGEM Software Technologies Research Institute.

Executive brief

A vulnerability exists in the update utility for Pardus, a Linux-based operating system. This flaw allows a user with limited access to the system to execute unauthorized commands with elevated privileges. This could lead to a complete system takeover, data loss, or unauthorized access to sensitive information.

Technical details

The vulnerability is classified as an OS command injection (CWE-78) within the pardus-update component of the Pardus operating system. It stems from the improper neutralization of special elements used in OS commands during the update process. An attacker with local access and low-level privileges can exploit this flaw to execute arbitrary code with the permissions of the update utility, typically root. The issue affects versions 0.6.6 through 0.6.9 and is resolved in version 0.7.0.

Affected products

  • TUBITAK BILGEM Software Technologies Research Institute pardus-update 0.6.6 to 0.6.9

Timeline

  • 2026-07-23: advisory: Published by NVD and TR-CERT

References