OS Command Injection Vulnerability in Pardus Boot Repair by TÜBİTAK BİLGEM
CVE-2026-19702

7.8HIGH

What is CVE-2026-19702?

A vulnerability exists in the Pardus Boot Repair software that allows an attacker to execute arbitrary operating system commands due to improper neutralization of special elements. This issue specifically affects versions 1.0.7 and prior to 1.0.8. By exploiting this weakness, malicious actors could potentially gain unauthorized access to the system and execute commands with elevated privileges, posing significant security risks to affected systems.

Affected Version(s)

Pardus Boot Repair 1.0.7 < 1.0.8

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mert Durum
.