Junglewise Threat Intelligence

CVE-2026-8304: TUBITAK BILGEM Pardus About missing authorization

CVE-2026-8304 · Severity: medium · CVSS 5.5 · Published 2026-09-11

Executive brief

Pardus About is a system information utility in the Pardus Linux distribution. A missing authorization vulnerability allows users to access or modify system information that should be restricted based on user privileges, potentially exposing sensitive configuration data or enabling unauthorized system changes.

Technical details

The vulnerability is a missing authorization (broken access control) issue in the Pardus About component, which fails to properly enforce access control checks on sensitive operations. An attacker with local access can bypass privilege level restrictions to read or modify system information that should be protected. The vulnerability affects versions 1.2.1 through 1.2.4. The attack vector is local, and no authentication bypass is required beyond existing system access. Patches are available in version 1.2.5 and later.

Affected products

  • TUBITAK BILGEM Pardus About 1.2.1 before 1.2.5

Timeline

  • 2026-09-11: disclosed
  • 2026-09-11: patched: Fixed in version 1.2.5

References