AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-18806

HIGH · CVSS 7.1 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The pardus-image-writer software prior to version 1.0.4 is vulnerable to an external control of file name or path issue, which could allow attackers to remove critical client functionality. This vulnerability poses a significant risk to users relying on this software for image writing, as it could lead to unauthorized modifications or disruptions in service. Organizations using this tool should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-18806
Severity
HIGH
CVSS
7.1
EPSS
0.10%

Original NVD Description

External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality. This issue affects pardus-image-writer: before 0.9.0.