External Control of File Name Vulnerability in TÜBİTAK BİLGEM pardus-image-writer
CVE-2026-18806

7.1HIGH

What is CVE-2026-18806?

An external control of file name or path vulnerability exists in the pardus-image-writer, developed by TÜBİTAK BİLGEM. This flaw allows unauthorized removal of critical client functionality, potentially leading to security risks. The issue affects versions prior to 1.0.4, making it crucial for users to apply the latest updates to safeguard their systems.

Affected Version(s)

pardus-image-writer 0 < 1.0.4

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Emirhan YÜCEL
.