Junglewise Threat Intelligence

CVE-2026-8303: TUBITAK BILGEM Pardus-software privilege escalation in privilege assignment

CVE-2026-8303 · Severity: high · CVSS 7.8 · Published 2026-09-11

Executive brief

Pardus-software, a system management tool for Linux distributions, contains a flaw in how it assigns user privileges. An attacker with limited local access could exploit this to escalate their permissions to administrator level, potentially gaining full control of the affected system.

Technical details

The vulnerability is an incorrect privilege assignment flaw in Pardus-software versions before 1.0.5. The issue allows privilege escalation, likely through mishandling of permission checks or default privilege configuration. The attack vector is local; an authenticated user on the system can exploit this to obtain elevated privileges. No information suggests remote exploitation or pre-authentication access is required. A patch is available in version 1.0.5 and later.

Affected products

  • TUBITAK BILGEM Pardus-software before 1.0.5

Timeline

  • 2026-09-11: disclosed

References