CVE-2026-8301
nicheOS Command Injection in TUBITAK BILGEM Pardus Boot Repair
CVE-2026-8301 is an OS command injection flaw (CWE-78) in Pardus Boot Repair, a boot-repair utility associated with Turkey's Pardus Linux distribution, developed by TUBITAK BILGEM. The tool fails to properly neutralize special elements before executing OS commands, so an attacker with low-privilege local access who can influence the tool's input can inject arbitrary operating-system commands. Because the CVSS 3.1 vector (AV:L/PR:L) is local with low privileges required and confidentiality, integrity and availability impacts rated high, successful exploitation likely lets a local user run commands with the elevated privileges of the boot-repair utility, potentially achieving full system compromise. Anyone running Pardus Boot Repair in versions before 1.0.8 is affected. There is currently no known public proof-of-concept, no inclusion in CISA KEV, and no reports of in-the-wild exploitation.
What to do: Upgrade Pardus Boot Repair to version 1.0.8 or later on all Pardus systems. Until patched, restrict untrusted local users on affected machines, since exploitation requires local low-privilege access. Check installed package versions on Pardus endpoints and monitor TUBITAK/USOM advisories for updated fixes or exploit reports.
| TUBITAK BILGEM Pardus Boot Repair | all versions before 1.0.8 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardus Boot Repair: before 1.0.8.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.