Junglewise Threat Intelligence

CVE-2026-6849: Pardus OS My Computer OS command injection

CVE-2026-6849 · Severity: high · CVSS 8.8 · Published 2026-04-29

Vendors: TUBITAK BILGEM Software Technologies Research Institute.

Executive brief

A security vulnerability has been identified in the 'My Computer' component of Pardus OS, a Linux-based operating system. This flaw allows an attacker to execute unauthorized commands on a user's system, potentially leading to a full system takeover or theft of sensitive data. Users are advised to update their software to version 0.8.0 or later to resolve this issue.

Technical details

An OS command injection vulnerability (CWE-78) exists in the 'My Computer' application of Pardus OS due to improper neutralization of special elements used in system commands. The vulnerability is reachable over the network and requires minimal user interaction (UI:R), allowing an unauthenticated attacker to execute arbitrary operating system commands with the privileges of the application. This can lead to complete compromise of confidentiality, integrity, and availability. The issue affects versions up to and including 0.7.5 and is fixed in version 0.8.0.

Affected products

  • TUBITAK BILGEM Software Technologies Research Institute Pardus OS My Computer <=0.7.5 before 0.8.0

Timeline

  • 2026-04-29: advisory: Initial publication of the vulnerability advisory.
  • 2026-04-29: disclosed
  • 2026-06-06: other: Last modified date in NVD record.

References