CVE-2026-102568: Pardus Parental Control before 0.7.0 Incorrect Authorization via PPCActivator.py
Pardus Parental Control before 0.7.0 contains an incorrect authorization vulnerability in the polkit policy that allows unprivileged local users to disable parental controls as root. Attackers can invoke PPCActivator.py with the --disable argument via pkexec to remove all restrictions including DNS filtering and application limits without authentication.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Pardus Parental Controlto a version that resolves this vulnerability.Fixed in 0.7.0
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
Any unprivileged local user on an affected system can exploit it. The attacker needs local access and the ability to invoke PPCActivator.py through pkexec; no additional authentication is required for the disable action.
What is the practical impact of successful exploitation?
An attacker can run the disable action as root and remove all parental-control restrictions. This includes DNS filtering and application limits.
Are systems running version 0.7.0 affected?
No. The vulnerability affects Pardus Parental Control versions before 0.7.0.
How can I determine whether parental controls may already have been disabled through this issue?
Check whether DNS filtering and application limits are still active. The vulnerable --disable action removes these restrictions.