Junglewise Threat Intelligence

CVE-2026-5141: TUBITAK BILGEM Pardus Software Center privilege escalation

CVE-2026-5141 · Severity: high · CVSS 8.8 · Published 2026-04-29

Vendors: TUBITAK BILGEM Software Technologies Research Institute.

Executive brief

Pardus Software Center, a tool used for managing and installing applications on the Pardus operating system, contains a security flaw in how it handles system permissions. An attacker could exploit this vulnerability to take control of high-privilege system processes. This could lead to unauthorized software installation, full system compromise, or the theft of sensitive data.

Technical details

A vulnerability involving Improper Privilege Management (CWE-269), Improper Access Control (CWE-284), and Incorrect Privilege Assignment (CWE-266) exists in the Pardus Software Center. The flaw allows an attacker to hijack a privileged process, potentially leading to local privilege escalation or unauthorized execution of administrative tasks. While the attack vector is listed as network-based, it requires user interaction (UI:R), suggesting the exploit may be triggered via malicious files or web-based delivery that interacts with the software center's handling of permissions. The issue is fixed in version 1.0.3.

Affected products

  • TUBITAK BILGEM Software Technologies Research Institute Pardus Software Center 1.0.2 to 1.0.3

Timeline

  • 2026-04-29: disclosed
  • 2026-04-29: advisory
  • 2026-06-06: other: Last modified date

References