Refine your search

1 vulnerability found for Pardus Boot Repair by TÜBİTAK BİLGEM Software Technologies Research Institute

CVE-2026-19702 (GCVE-0-2026-19702)
Vulnerability from cvelistv5
Published
2026-08-31 13:54
Modified
2026-08-31 14:25
CWE
  • CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
Summary
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardus Boot Repair: from 1.0.7 before 1.0.8.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-19702",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-31T14:25:40.472879Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-31T14:25:48.846Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Pardus Boot Repair",
          "vendor": "T\u00dcB\u0130TAK B\u0130LGEM Software Technologies Research Institute",
          "versions": [
            {
              "lessThan": "1.0.8",
              "status": "affected",
              "version": "1.0.7",
              "versionType": "custom"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Mert Durum"
        }
      ],
      "datePublic": "2026-08-31T13:31:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027) vulnerability in T\u00dcB\u0130TAK B\u0130LGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection.\u003cp\u003eThis issue affects Pardus Boot Repair: from 1.0.7 before 1.0.8.\u003c/p\u003e"
            }
          ],
          "value": "Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027) vulnerability in T\u00dcB\u0130TAK B\u0130LGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection.\n\nThis issue affects Pardus Boot Repair: from 1.0.7 before 1.0.8."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-88",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-88 OS Command Injection"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-78",
              "description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-31T13:54:45.791Z",
        "orgId": "ca940d4e-fea4-4aa2-9a58-591a58b1ce21",
        "shortName": "TR-CERT"
      },
      "references": [
        {
          "tags": [
            "government-resource"
          ],
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0956"
        }
      ],
      "source": {
        "advisory": "TR-26-0956",
        "defect": [
          "TR-26-0956"
        ],
        "discovery": "UNKNOWN"
      },
      "title": "OS Command Injection in T\u00dcB\u0130TAK B\u0130LGEM\u0027s Pardus Boot Repair",
      "x_generator": {
        "engine": "Vulnogram 1.0.5"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "ca940d4e-fea4-4aa2-9a58-591a58b1ce21",
    "assignerShortName": "TR-CERT",
    "cveId": "CVE-2026-19702",
    "datePublished": "2026-08-31T13:54:45.791Z",
    "dateReserved": "2026-08-13T08:07:57.415Z",
    "dateUpdated": "2026-08-31T14:25:48.846Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}