{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3atubitakpardus-software/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:tubitak:pardus-software:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-8303"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Pardus-software (\u003c 1.0.5)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","privilege-escalation","linux"],"_cs_type":"advisory","_cs_vendors":["TUBITAK BILGEM"],"content_html":"\u003cp\u003eCVE-2026-8303 is an incorrect privilege assignment vulnerability identified in the Pardus-software suite developed by the TUBITAK BILGEM Software Technologies Research Institute. The vulnerability exists in all versions prior to 1.0.5 and allows a local, authenticated attacker to escalate their privileges on an affected Pardus system. This flaw stems from a failure to correctly enforce access controls during privilege assignment, potentially allowing a non-privileged user to execute arbitrary commands or modify system configurations with higher-level permissions. Defenders should prioritize updating instances of Pardus-software to version 1.0.5 or later to mitigate the risk of local privilege escalation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability enables a local attacker to escalate privileges, potentially gaining full control over the underlying Pardus operating system. This could lead to unauthorized data access, system disruption, or the installation of persistent malicious backdoors within the victim environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Pardus-software to version 1.0.5 or later immediately.\u003c/li\u003e\n\u003cli\u003eImplement strict auditing of user privilege changes and account modifications on systems running Pardus-software.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-11T17:14:06Z","date_published":"2026-09-11T17:14:06Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-8303-pardus/","summary":"CVE-2026-8303 is an incorrect privilege assignment vulnerability in Pardus-software versions prior to 1.0.5 that allows local attackers to perform privilege escalation.","title":"Privilege Escalation Vulnerability in Pardus-software","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-8303-pardus/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:tubitak:pardus-Software:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}