CVE-2026-5140Disclosure

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper neutralization of CRLF sequences ('CRLF injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Authentication Bypass. This issue affects Pardus Update: from 0.6.3 before 0.6.4.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-93

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • Peaked 5d ago at 2 mentions (2026-04-29); latest day: 1
  • 7 total mentions across 6 days

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-04-29: 2Mentions · 2026-05-20: 1Mentions · 2026-05-21: 1Mentions · 2026-05-22: 1Mentions · 2026-05-27: 1Mentions · 2026-06-08: 1PoC Mentioned / Linked · 2026-05-21: 1Exploit Tool / Code · 2026-05-21: 1Patch / Workaround · 2026-04-29: 1Patch / Workaround · 2026-05-20: 1Technical Details · 2026-04-29: 2Technical Details · 2026-05-20: 1Technical Details · 2026-05-21: 1Technical Details · 2026-05-22: 1Technical Details · 2026-05-27: 1Technical Details · 2026-06-08: 104-2905-2005-2105-2205-2706-08
Signal classification4 categories
Disclosure
457.1%
Patch
114.3%
PoC
114.3%
General
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-292
Disclosure1Patch1
2026-05-201
Disclosure1
2026-05-211
PoC1
2026-05-221
Disclosure1
2026-05-271
Disclosure1
2026-06-081
General1
Full discourse7 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    توزيعة Pardus Linux المستخدمة في كثير من الجهات الحومية التركيه مصابه بثغره تسمح لأي مستخدم محلي يرفع صلاحياته لـ root بدون كلمة مرور. ثغرة CVE-2026-5140 بتصنيف 9.3 https://t.co/UN27JJDcEG

    Post summary

    The post announces the local privilege escalation CVE‑2026‑5140 affecting Pardus Linux, rating it 9.3, but it does not provide evidence of exploitation, a PoC, patch, or debunking.

    1001981.7K
    50.0K followersView on X
  • DFIR Radar@DFIR_Radar
    PoC

    Critical privilege escalation chain in Pardus Linux allows any local user to gain root access within seconds. CVE-2026-5140 scored CVSS 9.3, affecting Turkish 🇹🇷 government and enterprise systems nationwide. Technical breakdown: • Chain combines Polkit bypass + CRLF injection + untrusted search path in pardus-update package • Polkit misconfiguration in /usr/share/polkit-1/actions allows pkexec without authentication • http://SystemSettingsWrite.py vulnerable to \r injection, manipulating /etc/pardus/pardus-update.conf • http://AutoAptUpgrade.py copies attacker-controlled .list files to /etc/apt/sources.list.d/ without validation • Exploit creates malicious .deb package with postinst script: chmod +s /bin/bash Attack artifacts: • Monitor pkexec execution of http://SystemSettingsWrite.py and http://AutoAptUpgrade.py scripts • Check /etc/pardus/pardus-update.conf for unexpected custom_sourcesd_path entries • Audit /etc/apt/sources.list.d/ for unauthorized repository files • Watch for SUID bit changes on /bin/bash or other system binaries Hunt for recent pkexec processes with pardus-update arguments and correlate with APT package installations from non-standard repositories. #DFIR_Radar

    Post summary

    The post discloses a high‑severity privilege escalation chain in Pardus Linux, outlining the exploit flow, PoC scripts, and detection steps, but does not indicate current active exploitation or a mitigation.

    12050388
    1.8K followersView on X
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    General

    CVE-2026-5140: high severity (CVSS 8.8). TUBITAK BILGEM Software Technologies Research Institute Pardus has a authentication bypass issue worth scoping now. Scope it today so nobody has to explain it tomorrow.

    Post summary

    CVE-2026-5140 is an authentication bypass vulnerability with a high CVSS score of 8.8, but the text lacks detail about PoC, exploit code, patch, or active exploitation.

    1000057
    315 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-5140 — CVSS 9.6/10 ██████████ Improper neutralization of CRLF sequences ('CRLF injection') vulnerability in TUBITAK BILGEM Software Technologies... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/9bHKXLCcBi

    Post summary

    CVE-2026-5140 is a critical CRLF injection flaw in TUBITAK BILGEM Software Technologies, and a patch is urgently recommended.

    1000042
    25 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Pardus Linux の脆弱性 CVE-2026-5140:ローカル・サイレント昇格による root 権限の奪取 https://iototsecnews.jp/2026/05/20/pardus-linux-vulnerability-lets-local-attackers-gain-silent-root-access/ 今回の脆弱性である CVE-2026-5140 は、 3つの小さな問題が重なることで発生しています。原因の 1つ目は、認証の設定ミスにより、誰でも特権操作ができてしまったことです。2つ目は、入力された文字のチェックが不十分であり、 設定ファイルに不正な書き込みを許してしまったことです。そして 3つ目は、 信頼できない場所にあるファイルを検証せずに取り込んでしまったことです。それぞれが、単純なミスに見えるかもしれませんが、これらが組み合わさることで重大な脅威に繋がってしまいます。 ご利用のチームは、ご注意ください。 #CVE20265140 #Linux #Pardus #Vulnerability

    Post summary

    The article announces a local silent privilege escalation flaw in Pardus Linux (CVE‑2026‑5140), attributing it to authentication misconfiguration, poor input validation, and unchecked file imports, but does not provide any PoC, exploit, or patch details.

    0000098
    490 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Critical CVE-2026-5140 in Pardus Linux pardus-update allows local users to gain full root in seconds, CVSS 9.3, with no patch yet for widely deployed government systems. https://threatcluster.io/cluster/critical-privilege-escalation-vulnerability-in-pardus-linux--a09c3fec

    Post summary

    A critical privilege‑escalation CVE‑2026‑5140 in Pardus Linux pardus‑update can give local users root access, with a CVSS score of 9.3 and no patch currently available.

    0000086
    274 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5140 Improper neutralization of CRLF sequences ('CRLF injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus allows Authentication Bypas… https://www.cve.org/CVERecord?id=CVE-2026-5140

    Post summary

    The text announces a new CRLF injection vulnerability (CVE‑2026‑5140) affecting Pardus, providing only the basic CVE description and a reference link, with no PoC, exploit, or remediation details.

    00000117
    57.3K followersView on X

Explore more