Junglewise Threat Intelligence

CVE-2026-5140: TUBITAK BILGEM Pardus Update CRLF injection authentication bypass

CVE-2026-5140 · Severity: high · CVSS 8.8 · Published 2026-04-29

Vendors: TUBITAK BILGEM Software Technologies Research Institute.

Executive brief

A security vulnerability has been identified in the update component of Pardus, a Linux-based operating system. This flaw allows an attacker to bypass authentication mechanisms, potentially gaining unauthorized access to the system. Such an exploit could lead to the compromise of sensitive data or the disruption of system operations.

Technical details

A CRLF injection vulnerability (CWE-93) exists in the Pardus Update component due to improper neutralization of carriage return and line feed sequences. An attacker can exploit this flaw over the network to bypass authentication mechanisms. The vulnerability requires some user interaction (UI:R) and affects versions 0.6.3 through 0.6.4. Successful exploitation allows for high impact on confidentiality, integrity, and availability. A fix is available in version 0.6.4.

Affected products

  • TUBITAK BILGEM Software Technologies Research Institute Pardus Update 0.6.3 to 0.6.4

Timeline

  • 2026-04-29: disclosed
  • 2026-04-29: advisory

References