Incorrect Authorization Vulnerability in Pardus Parental Control Software
CVE-2026-102568

6.8MEDIUM

Key Information:

Vendor

Pardus

Vendor
CVE Published:
29 September 2026

What is CVE-2026-102568?

The Pardus Parental Control software prior to version 0.7.0 is susceptible to an incorrect authorization vulnerability that allows unprivileged local users to disable crucial parental control settings. By exploiting this issue, attackers can execute the PPCActivator.py script with the --disable option through the pkexec command, effectively removing all restrictions on internet access, including DNS filtering and application usage limits, without the need for authentication.

Affected Version(s)

pardus-parental-control 0 < 0.7.0

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yunus Aydın
.