CVE-2026-12250Disclosure

LOWCVSS 7.9 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Invocation of process using visible sensitive information vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Domain Joiner allows Excavation. This issue affects Pardus Domain Joiner: from 0.5.2 before 0.5.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-214

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-07-05: 3Patch / Workaround · 2026-07-05: 1Technical Details · 2026-07-05: 207-05
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-12250 Invocation of process using visible sensitive information vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Domain Joiner allows Excavat… https://www.cve.org/CVERecord?id=CVE-2026-12250 ----- Traducción: CVE-2026-12250 Inv… http://infoflow.cloud`

    Post summary

    The tweet merely cites CVE-2026-12250 and links to its CVE.org record, without additional technical or operational details.

    0000047
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-12250 Invocation of process using visible sensitive information vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Domain Joiner allows Excavat… https://www.cve.org/CVERecord?id=CVE-2026-12250

    Post summary

    The post simply announces CVE-2026-12250, identifies the vulnerable component, and links to the CVE record without indicating PoC, exploit availability, or mitigation.

    00000726
    57.7K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH severity CVE-2026-12250 (CVSS 7.9) Pardus Domain Joiner exposes sensitive info during process invocation. Affects versions 0.5.2 to <0.5.4. Update to 0.5.4+ immediately. #CVE #Vulnerability #PatchNow https://t.co/8XazYacZwV

    Post summary

    The tweet announces a high‑severity CVE (CVE‑2026‑12250) affecting Pardus Domain Joiner, warns of sensitive data exposure, and urges users to update to version 0.5.4 or newer.

    0000048
    61 followersView on X

Explore more