Description
Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Privilege Escalation.

This issue affects Pardus Update: from <=0.6.3 before 0.6.6.
Published: 2026-07-05
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in Pardus Update that permits users who can invoke privileged update functions to elevate their privileges. Classified as CWE‑862, the flaw indicates that the software does not enforce proper access controls, allowing an attacker to gain elevated permissions when the update service is triggered.

Affected Systems

The affected product is Pardus Update from TUBITAK BILGEM Software Technologies Research Institute. All releases prior to version 0.6.6, including 0.6.3 and earlier, contain the vulnerability.

Risk and Exploitability

The CVSS base score of 7.8 shows a high level of risk. The EPSS score of < 1% indicates only a very low probability of exploitation today, and the vulnerability does not appear in CISA's KEV catalog. The CVE description does not specify whether the flaw is exploitable locally or remotely, so the exact attack vector remains unknown. An attacker would need the ability to trigger the privileged update functions to exploit the missing authorization check.

Generated by OpenCVE AI on July 26, 2026 at 21:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Pardus Update to version 0.6.6 or later to address the missing authorization check.
  • Limit the update process to trusted or authenticated users by configuring appropriate access controls, reducing the risk of unauthorized privilege increase.
  • Monitor system logs and audit update activity for signs of abnormal or unauthorized use of the update service.

Generated by OpenCVE AI on July 26, 2026 at 21:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 05 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Privilege Escalation. This issue affects Pardus Update: from <=0.6.3 before 0.6.6.
Title Privilege Escalation in TUBITAK BILGEM's Pardus Update
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-06T13:21:56.311Z

Reserved: 2026-04-17T11:33:53.261Z

Link: CVE-2026-6509

cve-icon Vulnrichment

Updated: 2026-07-06T13:21:53.063Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T21:30:04Z

Weaknesses