
🚨 HIGH - Local DNS spoofing via permission misassignment in Pardus-Parental-Control (CVE-2026-9085) Pardus-Parental-Control is vulnerable to improper access control and incorrect permission assignment in its DNS control/enforcement components, allowing unauthorized modification of DNS-related settings. The root cause is an access control failure that grants low-privileged users capabilities that should be restricted to trusted/admin contexts. An attacker with local, low-privilege access can exploit this without user interaction by abusing the overly permissive configuration/controls to redirect DNS resolution. Impact includes DNS spoofing leading to traffic interception, credential theft via phishing, redirection to malicious updates, and broader compromise of systems relying on poisoned name resolution. 👉 Affected: Pardus-Parental-Control >=0.5.1 and <0.7.0 | Upgrade to 0.7.0
Post summary
The post highlights a local DNS spoofing flaw in Pardus-Parental-Control due to permission misassignment and recommends upgrading to version 0.7.0 for remediation.


