SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-16287

HIGH · CVSS 7.8 EPSS 0.47%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The pardus-update tool in versions prior to 0.7.0 is vulnerable to OS command injection due to improper handling of special elements in user input. This flaw could allow an attacker to execute arbitrary commands on the operating system, potentially leading to unauthorized access or system compromise. Organizations using affected versions of pardus-update should prioritize patching this vulnerability to mitigate the associated risks.

CVE
CVE-2026-16287
Severity
HIGH
CVSS
7.8
EPSS
0.47%

Original NVD Description

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command Injection. This issue affects pardus-update: from 0.6.6 before 0.7.0.