TUBITAK BILGEM's Pardus Software Center was disclosed with two high-severity vulnerabilities affecting versions prior to 1.0.3, including a privilege-management flaw tracked as CVE-2026-5141 and a path traversal issue tracked as CVE-2026-5166. The first bug was described as improper access control, incorrect privilege assignment, and improper privilege management, creating a condition that could allow hijacking of a privileged process; the affected range was later clarified as versions from 1.0.2 before 1.0.3.
The second flaw, CVE-2026-5166, was classified as CWE-22: Improper Limitation of a Pathname to a Restricted Directory and affects Pardus Software Center versions before 1.0.3. Both CVEs carry high-impact CVSS v3.1 ratings with vectors indicating low attack complexity and no required privileges, while requiring user interaction, and both reference advisories published by USOM, including TR-26-0131 for the path traversal vulnerability.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
A new CVE entry documented a path traversal vulnerability in Pardus Software Center caused by improper restriction of pathnames to a limited directory. The flaw affected versions before 1.0.3 and was assigned a high-severity CVSS v3.1 score.
A CVE entry was published for an improper privilege management and access control flaw in Pardus Software Center that could allow hijacking of a privileged process. The vulnerability affected version 1.0.2 before 1.0.3, with the affected range clarified in a later record modification.
USOM published advisory TR-26-0131 describing a path traversal flaw in TUBITAK BILGEM's Pardus Software Center affecting versions before 1.0.3. The issue was later tracked as CVE-2026-5166.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.