Description
Improper link resolution before file access ('link following') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus About allows Symlink Attack.

This issue affects Pardus About: before 1.2.2.
Published: 2026-04-29
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw stems from improper link resolution before file access in TUBITAK BILGEM's Pardus About. An attacker can create a symbolic link that points outside the intended directory, enabling the application to read or potentially write files it should not access. This vulnerability, identified as CWE‑59, can lead to the disclosure of confidential data and may allow modification of system files if the attack succeeds.

Affected Systems

The affected software is Pardus About from TUBITAK BILGEM Software Technologies Research Institute. All installations running a version earlier than 1.2.2 are vulnerable.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score is < 1%, indicating a very low probability of exploitation at this time. The issue is not listed in CISA's KEV catalog. The flaw can be exploited by crafting a malicious symbolic link that points to restricted files; while the description does not explicitly state the required conditions, it is inferred that the attack vector is primarily local or requires the attacker to create the link on a writable path used by the application.

Generated by OpenCVE AI on May 4, 2026 at 15:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Pardus About to version 1.2.2 or later.
  • If an upgrade is not immediately possible, restrict the application’s file access permissions to prevent following of symbolic links by disabling link resolution on directories containing sensitive files.
  • Conduct a file integrity check and monitor for unexpected file read operations.

Generated by OpenCVE AI on May 4, 2026 at 15:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 04 May 2026 13:30:00 +0000

Type Values Removed Values Added
Description Improper link resolution before file access ('link following') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus About allows Symlink Attack. This issue affects Pardus About: before v1.2.1. Improper link resolution before file access ('link following') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus About allows Symlink Attack. This issue affects Pardus About: before 1.2.2.

Thu, 30 Apr 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Tubitak Bilgem Software Technologies Research Institute
Tubitak Bilgem Software Technologies Research Institute pardus About
Vendors & Products Tubitak Bilgem Software Technologies Research Institute
Tubitak Bilgem Software Technologies Research Institute pardus About

Wed, 29 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Apr 2026 14:45:00 +0000

Type Values Removed Values Added
Description Improper link resolution before file access ('link following') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus About allows Symlink Attack. This issue affects Pardus About: before v1.2.1.
Title Improper Authentication in TUBITAK BILGEM's Pardus About
Weaknesses CWE-59
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Tubitak Bilgem Software Technologies Research Institute Pardus About
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-05-04T13:20:54.929Z

Reserved: 2026-03-30T14:30:28.693Z

Link: CVE-2026-5161

cve-icon Vulnrichment

Updated: 2026-04-29T14:52:57.082Z

cve-icon NVD

Status : Deferred

Published: 2026-04-29T15:16:08.010

Modified: 2026-05-04T14:16:35.300

Link: CVE-2026-5161

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-04T15:15:03Z

Weaknesses