CVE-2026-7863: OS Command Injection in TUBITAK BILGEM's Pardus Software
Published Sep 11, 2026
·Updated
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software allows OS Command Injection.
This issue affects Pardus Software: before 1.0.5.
Affected Software
1 affected component
TUBITAK BILGEM Software Technologies Research Institute Pardus Software<1.0.5
Event History
Sep 11, 2026
CVE Published
via MITRE·04:04 PM
Data Sourced
via MITRE·04:04 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Pardus Software versions before 1.0.5 are affected. The provided data does not identify specific deployment modes or configurations.
2
Does exploitation require authentication or user interaction?
The vector indicates no privileges are required and no user interaction is required. Exploitation is local (AV:L), so an attacker needs local access to the affected system.
3
What is the remediation?
Upgrade Pardus Software to version 1.0.5 or later. The provided information does not specify an alternative mitigation for systems that cannot be updated immediately.