Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-8303— Privilege Escalation in TUBITAK BILGEM's Pardus-software

Quick assessment

Affected
TUBITAK BILGEM Software Technologies Research Institute Pardus-software
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

这段漏洞描述信息的中文翻译如下: TUBITAK BILGEM 软件技术研究所的 Pardus-software 存在不正确的权限分配漏洞,可能导致权限提升(Privilege Escalation)。 该问题影响 Pardus-software:1.0.5 版本之前的版本。 --- 术语说明: Privilege Escalation:权限提升,指攻击者通过漏洞获得比正常用户更高的系统权限(例如从普通用户变为管理员)。 Incorrect privilege assignment:不正确的权限分配,指软件在分配用

CVSS 7.8 · High

Possible ATT&CK Techniques 1 AI

T1068.004
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-8303

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Privilege Escalation in TUBITAK BILGEM's Pardus-software
Source: CVE Program / CVE List V5
Vulnerability Description
Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-software allows Privilege Escalation. This issue affects Pardus-software: before 1.0.5.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
特权授予不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
TUBITAK BILGEM Software Technologies Research Institute Pardus-software 0 ~ 1.0.5 -

II. Public POCs for CVE-2026-8303

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-8303

登录查看更多情报信息。

Vendor Advisories for CVE-2026-8303 (1)

Same Patch Batch · TUBITAK BILGEM Software Technologies Research Institute · 2026-09-11 · 5 CVEs total

CVE-2026-7863 8.4 HIGH OS Command Injection in TUBITAK BILGEM's Pardus Software
CVE-2026-8301 7.8 HIGH OS Command Injection in TUBITAK BILGEM's Pardus-boot-repair
CVE-2026-8304 5.5 MEDIUM Information Disclosure in TUBITAK BILGEM's Pardus About
CVE-2026-11765 3.3 LOW Argument Injection in TUBITAK BILGEM's Pardus Pen

IV. Related Vulnerabilities

V. Comments for CVE-2026-8303

No comments yet


Leave a comment