Description
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command Injection.

This issue affects pardus-update: from 0.6.6 before 0.7.0.
Published: 2026-07-23
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker can exploit improper neutralization of special elements used in enabling them to execute arbitrary commands on the affected system. The vulnerability corresponds to CWE‑78 and, if leveraged, could compromise confidentiality, integrity, and availability by allowing the attacker to run any system command.

Affected Systems

The vulnerability affects the TUBITAK BILGEM Software Technologies Research Institute's pardus‑update utility, specifically versions 0.6.6 up to, but not including, 0.7.0. This product is used to implement offline system updates on Pardus distributions.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity risk. The EPSS score of less than 1 % suggests that, as exploitation is low, and the vulnerability is not currently listed in the CISA KEV catalog. Based on the description, the likely attack vector is local or an attacker that can supply without proper sanitization.

Generated by OpenCVE AI on August 3, 2026 at 22:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade pardus‑update to version 0.7.0 or later
  • If an immediate upgrade is not feasible, restrict write access to the directories used for storing update packages and validate that updates are obtained from trusted, signed sources
  • Enforce integrity checks, such as verifying cryptographic signatures, on update files before the update process is executed

Generated by OpenCVE AI on August 3, 2026 at 22:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Tubitak Bilgem Software Technologies Research Institute
Tubitak Bilgem Software Technologies Research Institute pardus Update
Vendors & Products Tubitak Bilgem Software Technologies Research Institute
Tubitak Bilgem Software Technologies Research Institute pardus Update

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command Injection. This issue affects pardus-update: from 0.6.6 before 0.7.0.
Title Root Command Injection via Offline Update in TÜBİTAK BİLGEM's pardus-update
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Tubitak Bilgem Software Technologies Research Institute Pardus Update
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-23T14:00:45.291Z

Reserved: 2026-07-20T12:08:18.724Z

Link: CVE-2026-16287

cve-icon Vulnrichment

Updated: 2026-07-23T14:00:42.554Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T09:16:26.570

Modified: 2026-07-23T15:01:24.377

Link: CVE-2026-16287

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:00:04Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')