Description
Incorrect Permission Assignment for Critical Resource, Improper Access Control vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-Parental-Control allows DNS Spoofing.

This issue affects Pardus-Parental-Control: from <=0.5.1 before 0.7.0.
Published: 2026-07-05
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from incorrect permission assignments to the DNS configuration component in TUBITAK BILGEM’s Pardus‑Parental‑Control, allowing an attacker to modify critical DNS resources. This flaw permits the injection of spoofed DNS responses, which can redirect traffic, facilitate phishing, or cause denial of service. Based on the description, it is inferred that an attacker capable of altering DNS records could manipulate domain resolution to their advantage.

Affected Systems

Pardus‑Parental‑Control versions 0.5.1 and earlier, and any build before 0.7.0, distributed by the TUBITAK BILGEM Software Technologies Research Institute, contain the vulnerable DNS configuration code and are therefore affected.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% suggests exploitation is currently unlikely but not impossible. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is inferred to require the ability to modify DNS configuration, either via local privilege or by exploiting a remote interface that grants such rights.

Generated by OpenCVE AI on July 26, 2026 at 21:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and apply any vendor patch or an upgrade newer than 0.7.0 that fixes the permission and access control issue.
  • Restrict file system permissions on the DNS configuration directory to administrators only to address the incorrect permission assignment (CWE‑732).
  • Disable or limit any remote interfaces that allow DNS configuration changes to mitigate improper access control (CWE‑284).
  • Continuously monitor DNS logs and the configuration directory for unauthorized modifications to detect potential spoofing attempts.

Generated by OpenCVE AI on July 26, 2026 at 21:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 05 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Description Incorrect Permission Assignment for Critical Resource, Improper Access Control vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-Parental-Control allows DNS Spoofing. This issue affects Pardus-Parental-Control: from <=0.5.1 before 0.7.0.
Title DNS Hijacking in TUBITAK BILGEM's Pardus-Parental-Control
Weaknesses CWE-284
CWE-732
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-06T13:24:46.535Z

Reserved: 2026-05-20T14:26:02.795Z

Link: CVE-2026-9085

cve-icon Vulnrichment

Updated: 2026-07-06T13:24:38.156Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T21:30:04Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-732

    Incorrect Permission Assignment for Critical Resource