CVE-2026-19702: OS Command Injection in TÜBİTAK BİLGEM's Pardus Boot Repair
Published Aug 31, 2026
·Updated
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection.
This issue affects Pardus Boot Repair: from 1.0.7 before 1.0.8.
Affected Software
1 affected component
Pardus Boot Repair>1.0.7<=1.0.8
Event History
Aug 31, 2026
CVE Published
via MITRE·01:54 PM
Data Sourced
via MITRE·01:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations need to be updated?
Pardus Boot Repair versions 1.0.7 through versions before 1.0.8 are affected. Updating to 1.0.8 or later removes the affected version range.
2
What level of access does an attacker need?
The CVSS vector indicates local attack access, no privileges required, and user interaction required. The provided information does not specify what user action triggers the vulnerable command handling.
3
What is the potential impact if exploitation succeeds?
The vulnerability can allow OS command injection. The CVSS metrics rate confidentiality, integrity, and availability impact as high.