CVE-2026-14460 is a missing authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software that allows argument injection. The issue affects pardus-software versions up to and including 1.0.4, and is fixed before 1.0.5. Based on the available information, the flaw stems from insufficient authorization checks protecting functionality that can be influenced with attacker-supplied arguments, enabling unauthorized use of that functionality through argument injection. Specific vulnerable functions or code paths are not provided in the available content.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains 4 files: a README plus three Bash scripts. It is a real local exploit repository targeting Pardus Software Center (pardus-software) 1.0.4 on Linux, covering two CVEs. The main exploit script exploit/exploit-14459.sh weaponizes CVE-2026-14459, a local privilege escalation via argument injection into the privileged Actions.py helper. It uses pkexec to call /usr/share/pardus/pardus-software/src/Actions.py with an injected apt option '-o Dir::Bin::dpkg=<temp_script>', causing apt to execute an attacker-controlled script as root. In default mode it stages a setuid-root shell at /tmp/.pdsh and execs it with '-p'; in command mode it runs a supplied shell command as root. This is an operational exploit with a basic hardcoded payload. The second exploit, exploit/exploit-14460.sh, targets CVE-2026-14460 by invoking /usr/share/pardus/pardus-software/src/AutoAptUpdate.py via pkexec as any local user, relying on a vulnerable PolicyKit action configured with allow_any=yes. Its capability is unauthenticated root apt-update execution, primarily useful for demonstrating or causing local denial of service through repeated package-management interference. The poc/poc.sh script is a benign multi-mode proof-of-concept: 'setup-victim' prepares a test user, mode 'A' builds a local unsigned .deb with a root-executed postinst, mode 'B' demonstrates the same apt option injection path as the main exploit, and 'autoupdate' demonstrates the missing-authorization issue. The repository purpose is to document, prove, and operationalize two local Pardus privilege/authorization flaws, with clear separation between benign PoC and exploit-ready scripts.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.