CVE-2026-102568 PUBLISHED

Pardus Parental Control before 0.7.0 Incorrect Authorization via PPCActivator.py

Assigner: VulnCheck
Reserved: 29.09.2026 Published: 29.09.2026 Updated: 29.09.2026

Pardus Parental Control before 0.7.0 contains an incorrect authorization vulnerability in the polkit policy that allows unprivileged local users to disable parental controls as root. Attackers can invoke PPCActivator.py with the --disable argument via pkexec to remove all restrictions including DNS filtering and application limits without authentication.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.8

Product Status

Vendor pardus
Product pardus-parental-control
Versions Default: unaffected
  • affected from 0 to 0.7.0 (excl.)

Credits

  • Yunus Aydın finder

References

Problem Types

  • Incorrect Authorization CWE