CVE-2026-5166Disclosure

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software Center allows Path Traversal. This issue affects Pardus Software Center: before 0.6.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-29); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-29: 3Mentions · 2026-05-02: 1Patch / Workaround · 2026-04-29: 1Patch / Workaround · 2026-05-02: 1Technical Details · 2026-04-29: 3Technical Details · 2026-05-02: 104-2905-02
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
General
125.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-293
Disclosure2Patch1
2026-05-021
General1
Full discourse4 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-5166 — CVSS 9.6/10 ██████████ Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TUBITAK BILGEM Software... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/vGWK27t4HP

    Post summary

    CVE-2026-5166 is a critical path traversal flaw in TUBITAK BILGEM Software with a CVSS score of 9.6/10. A patch has already been released to address the vulnerability.

    1000038
    25 followersView on X
  • z3n@zench4n
    General

    Practical takeaway: Don't just audit the model. Audit the bridge between the LLM and the OS. If your agent can trigger a path traversal like CVE-2026-5166, your sandbox is a suggestion, not a barrier. Implement eBPF-based monitoring for all agentic tool execution.

    Post summary

    The passage highlights that a path traversal CVE like CVE-2026-5166 can bypass sandboxing and advises implementing eBPF-based monitoring to mitigate risk.

    0000040
    1.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5166 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software … https://www.cve.org/CVERecord?id=CVE-2026-5166 ----- Traducción: CVE-2026-5166 Lim… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑5166, a path traversal flaw in Pardus Software from TUBITAK BILGEM, providing minimal details and a link to the official CVE record.

    0000038
    74 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5166 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software … https://www.cve.org/CVERecord?id=CVE-2026-5166

    Post summary

    The post simply links to the CVE record for a Path Traversal vulnerability in Pardus Software, providing minimal technical detail but no evidence of PoC, exploit, active exploitation, patch, or false positive claims.

    00000124
    57.3K followersView on X

Explore more