Junglewise Threat Intelligence

CVE-2026-9085: TUBITAK BILGEM Pardus-Parental-Control DNS spoofing via improper access control

CVE-2026-9085 · Severity: high · CVSS 8.8 · Published 2026-07-05

Vendors: TUBITAK BILGEM Software Technologies Research Institute.

Executive brief

Pardus-Parental-Control is a software tool used to manage and restrict internet access for users on the Pardus operating system. A security flaw in how the software manages file permissions allows a local user to bypass web filters and redirect internet traffic to malicious websites. This could lead to the theft of login credentials or the installation of malware on the affected system.

Technical details

A vulnerability exists in Pardus-Parental-Control versions 0.5.1 through 0.6.x (fixed in 0.7.0) due to incorrect permission assignments (CWE-732) and improper access control (CWE-284). A local attacker with low privileges can exploit these weak permissions to modify critical system resources, specifically enabling DNS spoofing. By redirecting DNS queries, the attacker can intercept or manipulate network traffic. The vulnerability is characterized by a CVSS 3.1 score of 8.8, noting a scope change (S:C) which indicates the impact extends beyond the parental control application to the broader system network security.

Affected products

  • TUBITAK BILGEM Software Technologies Research Institute Pardus-Parental-Control >=0.5.1, <0.7.0

Timeline

  • 2026-07-05: advisory: CVE-2026-9085 published by TR-CERT and NVD
  • 2026-07-05: disclosed

References