Description
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection.

This issue affects Pardus Boot Repair: before 1.0.8.
Published: 2026-09-11
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: OS Command Injection
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an OS command injection in Pardus Boot Repair. The application fails to neutralize special elements used in an OS command, allowing an attacker to inject arbitrary shell commands. If an attacker can trigger the affected functionality, they could execute commands with the privileges of the process, potentially gaining full system control. The weakness is classified as CWE-78.

Affected Systems

TUBITAK BILGEM Software Technologies Research Institute offers Pardus Boot Repair. Versions prior to 1.0.8 are affected. Upgrading to version 1.0.8 or later removes the vulnerability.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, and the EPSS score is unavailable. The vulnerability is not currently listed in the CISA KEV catalog. Because the tool operates with elevated privileges to modify boot configuration, the likely attack vector is a local user or an attacker with access to the repair utility. An exploit could lead to arbitrary code execution, compromising confidentiality, integrity, and availability of the affected system.

Generated by OpenCVE AI on September 11, 2026 at 16:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Pardus Boot Repair to version 1.0.8 or later.
  • If an update is not immediately possible, restrict the executable’s permissions so only authorized users can run it, or disable the command execution features it uses.
  • Monitor system logs for attempts to invoke the tool with suspicious parameters and audit any anomalous activity.

Generated by OpenCVE AI on September 11, 2026 at 16:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardus Boot Repair: before 1.0.8.
Title OS Command Injection in TUBITAK BILGEM's Pardus-boot-repair
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-11T15:01:38.863Z

Reserved: 2026-05-11T10:42:19.155Z

Link: CVE-2026-8301

cve-icon Vulnrichment

Updated: 2026-09-11T15:01:33.545Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T15:17:09.540

Modified: 2026-09-11T17:35:21.440

Link: CVE-2026-8301

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T16:30:08Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')