CVE-2026-5140: Authorization Bypass in TUBITAK BILGEM's Pardus Update
Improper neutralization of CRLF sequences ('CRLF injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Authentication Bypass.
This issue affects Pardus Update: from 0.6.3 before 0.6.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5140?
CVE-2026-5140 is classified as a high severity vulnerability due to the potential for authentication bypass.
How do I fix CVE-2026-5140?
To mitigate CVE-2026-5140, update to a version of TUBITAK BILGEM's Pardus software that is greater than 0.8.0.
What does CVE-2026-5140 affect?
CVE-2026-5140 affects TUBITAK BILGEM's Pardus versions from 0.6.4 up to, but not including, 0.8.0.
What is a CRLF injection related to CVE-2026-5140?
CRLF injection in CVE-2026-5140 refers to the vulnerability that allows an attacker to bypass authorization controls due to improper handling of CRLF sequences.
Is CVE-2026-5140 exploitative?
Yes, CVE-2026-5140 can be exploited to gain unauthorized access to systems that utilize the vulnerable versions of Pardus.