Researchers disclosed CVE-2026-5140, a critical local privilege escalation chain in Pardus Linux that lets any unprivileged local user gain root access without authentication through the pardus-update package. The flaw carries a CVSS v3.1 score of 9.3 and was identified by security researcher Çağrı Eser (0xc4gr1). The issue combines three weaknesses: an overly permissive Polkit policy, a CRLF injection flaw in SystemSettingsWrite.py, and an untrusted search path issue in AutoAptUpgrade.py.
Attackers can exploit the chain by injecting a malicious APT source path, causing the system to install a crafted Debian package with elevated privileges, and then obtaining a root shell by setting the SUID bit on /bin/bash. The exposure is particularly serious because Pardus Linux, maintained by TÜBİTAK, is widely deployed across Turkish government, education, and enterprise environments, especially on shared or multi-user systems. Recommended mitigations include tightening Polkit rules to require administrator authentication, sanitizing carriage return and newline characters in user input, and restricting APT source paths to trusted directories.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers publicly disclosed the Pardus Linux privilege escalation flaw, explaining that an unprivileged local user could inject a malicious APT source, install a crafted package as root, and obtain a root shell. The disclosure assigned the issue a CVSS 9.3 severity and recommended tightening Polkit rules, sanitizing CRLF input, and restricting APT source paths to trusted directories.
Security researcher Çağrı Eser documented a critical local privilege escalation chain in the Pardus Linux pardus-update package, later tracked as CVE-2026-5140. The chain combined an overly permissive Polkit policy, a CRLF injection flaw in SystemSettingsWrite.py, and an untrusted search path issue in AutoAptUpgrade.py to let a local user gain root access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
thecyberexpress.com
Open sourcecybersecuritynews.com
Open sourcenullsecurityx.medium.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.