Junglewise Threat Intelligence

CVE-2026-6509: TUBITAK BILGEM Pardus Update privilege escalation

CVE-2026-6509 · Severity: high · CVSS 7.8 · Published 2026-07-05

Vendors: TUBITAK BILGEM Software Technologies Research Institute.

Executive brief

A security vulnerability has been identified in the update utility for Pardus, a Linux-based operating system. This flaw allows a user with low-level access to bypass security checks and gain administrative control over the system. An attacker could use this to access sensitive files, modify system settings, or disrupt operations.

Technical details

A Missing Authorization vulnerability (CWE-862) exists in the Pardus Update component of the Pardus operating system. The flaw is located in the update mechanism, where insufficient permission checks allow a local user with low privileges to execute commands with elevated (root) permissions. The attack vector is local, requiring no user interaction or complex configurations. This issue affects versions from 0.6.3 and earlier, and is addressed in version 0.6.6.

Affected products

  • TUBITAK BILGEM Software Technologies Research Institute Pardus Update from <=0.6.3 before 0.6.6

Timeline

  • 2026-07-05: disclosed
  • 2026-07-05: advisory

References