CVE-2026-8301: OS Command Injection in TUBITAK BILGEM's Pardus-boot-repair
Published Sep 11, 2026
·Updated
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection.
This issue affects Pardus Boot Repair: before 1.0.8.
Affected Software
1 affected component
TUBITAK BILGEM Software Technologies Research Institute Pardus Boot Repair<1.0.8
Event History
Sep 11, 2026
CVE Published
via MITRE·02:42 PM
Data Sourced
via MITRE·02:42 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs local access and low-level privileges on the affected system. No user interaction is required.
2
Which installations are affected?
Pardus Boot Repair versions before 1.0.8 are affected. The provided information does not state whether the vulnerable behavior is enabled in a default configuration.
3
What is the impact of successful exploitation?
Successful exploitation can allow execution of OS commands and can affect confidentiality, integrity, and availability of the affected system.