ZeroHour

CVE-2026-8303

large

Local privilege escalation flaw in TUBITAK BILGEM Pardus-software

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-8303 is an incorrect privilege assignment flaw (CWE-266) in Pardus-software, a component of the Pardus Linux distribution developed by Turkey's TUBITAK BILGEM Software Technologies Research Institute. Affected versions before 1.0.5 assign privileges incorrectly, so a local user with low privileges can trigger the flaw with no user interaction required and escalate to higher privileges, likely gaining full control of the system given the high confidentiality, integrity, and availability impact ratings. The CVSS:3.1 local attack vector (AV:L/PR:L/UI:N) means exploitation requires an attacker to already have a foothold, such as a local account or the ability to run code on the machine, rather than remote network access. Anyone running Pardus with a Pardus-software version prior to 1.0.5 is affected. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported to date.

What to do: Update Pardus-software to version 1.0.5 or later via Pardus package repositories on all Pardus installations. Until patched, treat multi-user or shared Pardus machines as higher risk, since any local account could potentially escalate privileges. Monitor USOM (TR-CERT) advisories for updates on exploitation status.

Affected
TUBITAK BILGEM Software Technologies Research Institute Pardus-softwareall versions before 1.0.5
Estimated exposure
largeorder of 100k–1M users (estimated; Pardus is a niche national Linux distribution deployed primarily in Turkish public institutions and education) — Pardus is the Turkish national Linux distribution with a user base concentrated in government and education deployments, suggesting a six-figure user base is plausible, but no public active-install or scan data is available, so this is a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-software allows Privilege Escalation. This issue affects Pardus-software: before 1.0.5.

Weakness
CWE-266
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.