2026-04-29 14:42CVE-2026-6849TR-CERT
PUBLISHED5.2CWE-78

OS Command Injection in TUBITAK BILGEM's Pardus OS My Computer

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus OS My Computer allows OS Command Injection.

This issue affects Pardus OS My Computer: from <=0.7.5 before 0.8.0.

Problem type

Affected products

TUBITAK BILGEM Software Technologies Research Institute

Pardus OS My Computer

< 0.8.0 - AFFECTED

References

GitHub Security Advisories

GHSA-7v3p-wpx4-69fx

Improper neutralization of special elements used in an OS command ('OS command injection')...

https://github.com/advisories/GHSA-7v3p-wpx4-69fx

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus OS My Computer allows OS Command Injection.

This issue affects Pardus OS My Computer: from <=0.7.5 before 0.8.0.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-6849
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-6849",
    "assignerOrgId": "ca940d4e-fea4-4aa2-9a58-591a58b1ce21",
    "assignerShortName": "TR-CERT",
    "dateUpdated": "2026-04-29T15:35:39.447Z",
    "dateReserved": "2026-04-22T08:58:42.292Z",
    "datePublished": "2026-04-29T14:42:29.339Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "ca940d4e-fea4-4aa2-9a58-591a58b1ce21",
        "shortName": "TR-CERT",
        "dateUpdated": "2026-04-29T14:42:29.339Z"
      },
      "datePublic": "2026-04-29T14:36:00.000Z",
      "title": "OS Command Injection in TUBITAK BILGEM's Pardus OS My Computer",
      "descriptions": [
        {
          "lang": "en",
          "value": "Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus OS My Computer allows OS Command Injection.\n\nThis issue affects Pardus OS My Computer: from <=0.7.5 before 0.8.0.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus OS My Computer allows OS Command Injection.<p>This issue affects Pardus OS My Computer: from &lt;=0.7.5 before 0.8.0.</p>"
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "TUBITAK BILGEM Software Technologies Research Institute",
          "product": "Pardus OS My Computer",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "<=0.7.5",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "0.8.0"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')",
              "cweId": "CWE-78",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://www.usom.gov.tr/bildirim/tr-26-0131",
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-88",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-88 OS Command Injection"
            }
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ],
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH"
          }
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Osman Can VURAL",
          "type": "finder"
        }
      ]
    },
    "adp": [
      {
        "providerMetadata": {
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP",
          "dateUpdated": "2026-04-29T15:35:39.447Z"
        },
        "title": "CISA ADP Vulnrichment",
        "metrics": [
          {}
        ]
      }
    ]
  }
}