CVE-2026-7863
nicheOS Command Injection in TUBITAK BILGEM Pardus Software before 1.0.5
CVE-2026-7863 is an OS command injection flaw (CWE-78) in Pardus Software, a component associated with Turkey's TUBITAK BILGEM-developed Pardus Linux ecosystem, affecting all versions before 1.0.5. Improperly neutralized special elements allow injected OS commands to be executed when attacker-controlled input reaches the vulnerable component; the CVSS vector (AV:L/PR:N/UI:N) indicates exploitation occurs via a local attack vector with no privileges or user interaction required. A successful attack yields arbitrary OS command execution with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 8.4, High). Users and administrators running Pardus Software versions prior to 1.0.5 are affected, a population concentrated in Turkish public-sector and desktop deployments of the Pardus distribution. There are currently no known public proofs of concept, no reports of in-the-wild exploitation, and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog; it was assigned by Turkey's USOM as CNA.
What to do: Update Pardus Software to version 1.0.5 or later via Pardus package repositories, and verify the installed version on affected systems. Because the attack vector is local, prioritize systems where untrusted or low-privileged local users can run the vulnerable component (e.g., multi-user or kiosk-style machines), and restrict local access where upgrading is not yet possible. No public exploit is known, but monitor Pardus/USOM advisories as details and fixes propagate.
| TUBITAK BILGEM Software Technologies Research Institute Pardus Software | all versions before 1.0.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software allows OS Command Injection. This issue affects Pardus Software: before 1.0.5.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.