CVE-2026-19702
nicheOS Command Injection in TÜBİTAK BİLGEM Pardus Boot Repair 1.0.7
CVE-2026-19702 is an OS command injection flaw (CWE-78) in Pardus Boot Repair, a utility from TÜBİTAK BİLGEM Software Technologies Research Institute for the Turkish Pardus Linux distribution. The vulnerability arises because the tool fails to properly neutralize special elements before using them in OS commands, so an attacker who can supply or influence input that reaches a shell command can inject and execute arbitrary commands; per the CVSS scoring (AV:L, UI:R), this requires local access and user interaction. A successful attack yields high-impact loss of confidentiality, integrity, and availability (CVSS 3.1 score 7.8), with the commands running in the context of the affected application. Only systems running Pardus Boot Repair version 1.0.7 (and later versions below 1.0.8) are affected, meaning a subset of Pardus Linux deployments, concentrated in Turkey including public-sector installations. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is currently known, and EPSS estimates the 30-day exploitation probability at roughly 0.5%.
What to do: Upgrade Pardus Boot Repair to version 1.0.8 or later using official Pardus repositories and verify the installed package version on affected systems. Because exploitation requires local access and user interaction, prioritize shared or multi-user Pardus machines where untrusted users could influence the tool's input, and monitor USOM/TÜBİTAK advisories for follow-up updates.
| TÜBİTAK BİLGEM Software Technologies Research Institute Pardus Boot Repair | >= 1.0.7 and < 1.0.8 (fixed in 1.0.8) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardus Boot Repair: from 1.0.7 before 1.0.8.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.