Home

Description

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus OS My Computer allows OS Command Injection. This issue affects Pardus OS My Computer: from <=0.7.5 before 0.8.0.

PUBLISHED Reserved 2026-04-22 | Published 2026-04-29 | Updated 2026-04-29 | Assigner TR-CERT




HIGH: 8.8CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Problem types

CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')

Product status

Default status
unaffected

<=0.7.5 (custom) before 0.8.0
affected

Credits

Osman Can VURAL finder

References

www.usom.gov.tr/bildirim/tr-26-0131 third-party-advisory

cve.org (CVE-2026-6849)

nvd.nist.gov (CVE-2026-6849)

Download JSON