CVE-2026-12250 PUBLISHED

Sensitive Data Exposure in TUBITAK BILGEM's Pardus Domain Joiner

Assigner: TR-CERT
Reserved: 15.06.2026 Published: 05.07.2026 Updated: 05.07.2026

Invocation of process using visible sensitive information vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Domain Joiner allows Excavation.

This issue affects Pardus Domain Joiner: from 0.5.2 before 0.5.4.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
CVSS Score: 7.9

Product Status

Vendor TUBITAK BILGEM Software Technologies Research Institute
Product Pardus Domain Joiner
Versions Default: unaffected
  • affected from 0.5.2 to 0.5.4 (excl.)

Credits

  • Tacettin KARADENİZ finder

References

Problem Types

  • CWE-214 Invocation of process using visible sensitive information CWE

Impacts

  • CAPEC-116 Excavation