CVE-2026-16287 PUBLISHED

Root Command Injection via Offline Update in TÜBİTAK BİLGEM's pardus-update

Assigner: TR-CERT
Reserved: 20.07.2026 Published: 23.07.2026 Updated: 23.07.2026

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command Injection.

This issue affects pardus-update: from 0.6.6 before 0.7.0.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.8

Product Status

Vendor TUBITAK BILGEM Software Technologies Research Institute
Product pardus-update
Versions Default: unaffected
  • affected from 0.6.6 to 0.7.0 (excl.)

Credits

  • Ahmet Sadık ŞAHİNER finder

References

Problem Types

  • CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') CWE

Impacts

  • CAPEC-88 OS Command Injection