
🚨High - Pardus Software Center Argument Injection & Missing Authorization (CVE-2026-14459, CVE-2026-14460) Two flaws in Pardus software, the application-management GUI of Pardus Linux (TÜBİTAK BİLGEM). CVE-2026-14459 is an argument injection issue (CWE-88): improper neutralization of argument delimiters lets a low-privileged local user inject extra command-line arguments into a command the app executes. CVE-2026-14460 is a missing authorization flaw (CWE-862) that enables the same argument injection by exposing an operation without a proper authorization check. Both are local, low-privilege, no user interaction, with a scope change and high confidentiality, integrity, and availability impact. 👉Fixed in pardus-software 1.0.5 (affects <= 1.0.4).
Post summary
Two local low-privilege argument injection and missing authorization flaws (CVE-2026-14459, CVE-2026-14460) in Pardus Software Center have been disclosed, with high impact, and a patch is available in pardus-software 1.0.5.


