Junglewise Threat Intelligence

CVE-2026-5166: TUBITAK BILGEM Pardus Software Center path traversal

CVE-2026-5166 · Severity: critical · CVSS 9.6 · Published 2026-04-29

Vendors: TUBITAK BILGEM Software Technologies Research Institute.

Executive brief

A path traversal vulnerability exists in the Pardus Software Center, a tool used for managing and installing software on the Pardus operating system. This flaw could allow an attacker to access or manipulate sensitive files on the system that should normally be restricted. Such an exploit could lead to the theft of private data, system instability, or a complete takeover of the affected machine.

Technical details

A path traversal vulnerability (CWE-22) exists in the Pardus Software Center prior to version 0.6.4. The flaw stems from improper limitation of pathnames to a restricted directory, allowing an attacker to escape the intended file structure. According to the CVSS vector, the attack is network-reachable and requires minimal complexity, though it may involve some user interaction. Successful exploitation can lead to full compromise of confidentiality, integrity, and availability (C/I/A) with scope change, potentially allowing arbitrary file read or write access on the host system. Users are advised to upgrade to version 0.6.4 or later.

Affected products

  • TUBITAK BILGEM Software Technologies Research Institute Pardus Software Center before 0.6.4

Timeline

  • 2026-04-29: disclosed
  • 2026-04-29: advisory
  • 2026-06-06: other: Last modified date

References