Privilege Escalation Vulnerability in Pardus-software
CVE-2026-8303 is an incorrect privilege assignment vulnerability in Pardus-software versions prior to 1.0.5 that allows local attackers to perform privilege escalation.
CVE search metadata
CVE search record: CVE-2026-8303. Severity: high. CVSS: 7.8. KEV: no. Product: Pardus-software (< 1.0.5). Brief: Privilege Escalation Vulnerability in Pardus-software. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-8303-pardus/
CVE-2026-8303 is an incorrect privilege assignment vulnerability identified in the Pardus-software suite developed by the TUBITAK BILGEM Software Technologies Research Institute. The vulnerability exists in all versions prior to 1.0.5 and allows a local, authenticated attacker to escalate their privileges on an affected Pardus system. This flaw stems from a failure to correctly enforce access controls during privilege assignment, potentially allowing a non-privileged user to execute arbitrary commands or modify system configurations with higher-level permissions. Defenders should prioritize updating instances of Pardus-software to version 1.0.5 or later to mitigate the risk of local privilege escalation.
Impact
Successful exploitation of this vulnerability enables a local attacker to escalate privileges, potentially gaining full control over the underlying Pardus operating system. This could lead to unauthorized data access, system disruption, or the installation of persistent malicious backdoors within the victim environment.
Recommendation
- Upgrade all instances of Pardus-software to version 1.0.5 or later immediately.
- Implement strict auditing of user privilege changes and account modifications on systems running Pardus-software.
Mitigations
Upgrade Pardus-software to version 1.0.5 or later
CVE-2026-8303