Description
Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection.

This issue affects pardus-software: from <= 1.0.4 before 1.0.5.
Published: 2026-07-03
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization check that allows an attacker to inject arbitrary arguments into TUBITAK BILGEM Software Technologies Research Institute’s pardus-software. This enables manipulation of the software’s behavior in unintended ways and is classified as CWE‑862.

Affected Systems

All deployments of pardus-software version 1.0.4 or earlier by TUBITAK BILGEM Software Technologies Research Institute. The issue is resolved in version 1.0.5 and later.

Risk and Exploitability

Based on the description, the likely attack vector is an interface that accepts arguments without proper access control—such as a command‑line option, script, or API call. The CVSS score of 8.8 indicates a high severity level. The EPSS score of less than 1% suggests a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, indicating no publicly known exploitation data.

Generated by OpenCVE AI on July 22, 2026 at 13:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade pardus-software to version 1.0.5 or later to apply the missing authorization fix.
  • If an immediate upgrade is not feasible, restrict the vulnerable parameter interface to trusted users only by configuring access controls or firewall rules to block unauthenticated access.
  • Implement input validation or parameter whitelisting to ensure only expected argument values are processed, rejecting or sanitizing unexpected inputs.

Generated by OpenCVE AI on July 22, 2026 at 13:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. This issue affects pardus-software: from <= 1.0.4 before 1.0.5.
Title Missing Authorization in TUBITAK BILGEM's pardus-software
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-06T15:55:22.415Z

Reserved: 2026-07-02T08:47:10.200Z

Link: CVE-2026-14460

cve-icon Vulnrichment

Updated: 2026-07-06T15:55:18.392Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T13:15:12Z

Weaknesses