Description
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection.

This issue affects Pardus Boot Repair: from 1.0.7 before 1.0.8.
Published: 2026-08-31
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unmanaged input leads to OS command injection in Pardus Boot Repair, allowing an attacker to execute arbitrary shell commands. The vulnerability can compromise confidentiality, integrity, and availability of the affected system, potentially giving an attacker full control if executed with elevated privileges.

Affected Systems

The flaw exists in TÜBİTAK BİLGEM Software Technologies Research Institute's Pardus Boot Repair utility, specifically versions 1.0.7 and any earlier releases prior to 1.0.8.

Risk and Exploitability

The CVSS score of 7.8 indicates substantial risk. No EPSS score is available and the vulnerability is not listed in CISA's KEV catalog. The attack vector is not explicitly disclosed in the description; the likely scenario requires local or privileged access to run the boot repair tool, or remote exposure if the utility is otherwise accessible. Because the attack path is uncertain, it is prudent to assume the vulnerability could be leveraged by a malicious actor with user or higher privileges within the system.

Generated by OpenCVE AI on August 31, 2026 at 15:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Pardus Boot Repair to version 1.0.8 or later, which contains the fix for the command injection flaw.
  • If an upgrade is impossible in the short term, remove or disable the reboot repair utility until the patched version is available to prevent accidental invocation.
  • Restrict execution of the utility to trusted administrators and run it with the minimum privileges required, to limit the impact of any potential exploit.

Generated by OpenCVE AI on August 31, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardus Boot Repair: from 1.0.7 before 1.0.8.
Title OS Command Injection in TÜBİTAK BİLGEM's Pardus Boot Repair
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-31T14:25:48.846Z

Reserved: 2026-08-13T08:07:57.415Z

Link: CVE-2026-19702

cve-icon Vulnrichment

Updated: 2026-08-31T14:25:45.546Z

cve-icon NVD

Status : Received

Published: 2026-08-31T14:17:14.047

Modified: 2026-08-31T15:17:12.430

Link: CVE-2026-19702

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T15:30:04Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')