ZeroHour

CVE-2026-19702

niche

OS Command Injection in TÜBİTAK BİLGEM Pardus Boot Repair 1.0.7

CVSS 3.1
7.8 high
EPSS
<1%p41
Published
()
Modified
AI analysis

CVE-2026-19702 is an OS command injection flaw (CWE-78) in Pardus Boot Repair, a utility from TÜBİTAK BİLGEM Software Technologies Research Institute for the Turkish Pardus Linux distribution. The vulnerability arises because the tool fails to properly neutralize special elements before using them in OS commands, so an attacker who can supply or influence input that reaches a shell command can inject and execute arbitrary commands; per the CVSS scoring (AV:L, UI:R), this requires local access and user interaction. A successful attack yields high-impact loss of confidentiality, integrity, and availability (CVSS 3.1 score 7.8), with the commands running in the context of the affected application. Only systems running Pardus Boot Repair version 1.0.7 (and later versions below 1.0.8) are affected, meaning a subset of Pardus Linux deployments, concentrated in Turkey including public-sector installations. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is currently known, and EPSS estimates the 30-day exploitation probability at roughly 0.5%.

What to do: Upgrade Pardus Boot Repair to version 1.0.8 or later using official Pardus repositories and verify the installed package version on affected systems. Because exploitation requires local access and user interaction, prioritize shared or multi-user Pardus machines where untrusted users could influence the tool's input, and monitor USOM/TÜBİTAK advisories for follow-up updates.

Affected
TÜBİTAK BİLGEM Software Technologies Research Institute Pardus Boot Repair>= 1.0.7 and < 1.0.8 (fixed in 1.0.8)
Estimated exposure
nichelikely thousands to tens of thousands of Pardus installations at most, and only those running Boot Repair 1.0.7 (est.) — Pardus is a national Turkish Linux distribution deployed mainly in Turkish public institutions with no published install counts, and the flaw affects a single utility version range, so only a subset of Pardus systems is exposed — this is a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardus Boot Repair: from 1.0.7 before 1.0.8.

Weakness
CWE-78
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.