A chain of local privilege escalation vulnerabilities, codenamed CVE-2026–5140, has exposed serious security flaws in Pardus Linux. Researchers have revealed that the flaws allow any unprivileged local user to gain full root access without authentication, potentially leading to a complete system compromise within seconds. The vulnerability affects the pardus-update, which manages system updates via graphical tools and privileged Python helper scripts. The issue has received a CVSS v3.1 score of 9.3/10, classifying it as “Critical.”

The published vector is: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Pardus Linux, which is maintained by TÜBİTAK, is widely used in Turkish government institutions, schools, and business environments. The researchers said the attack chain behind CVE-2026–5140 combines three separate vulnerabilities: a Polkit authorization bypass, a CRLF injection vulnerability, and an untrusted search path issue.
See also: Drupal Core vulnerability allows RCE attacks on PostgreSQL sites
Polkit Misconfiguration Opens the Door for Attack
The first issue was detected in the file: /usr/share/polkit-1/actions/tr.org.pardus.pkexec.pardus-update.policy
The researchers discovered that several privileged actions were configured with unchecked access rights :
<defaults>
<allow_any>yes</allow_any>
<allow_inactive>yes</allow_inactive>
<allow_active>yes</allow_active>
</defaults>
Because of this configuration, any local user could perform privileged operations via pkexec without entering an administrator password.
The vulnerable actions included aptupdateaction, autoaptupgradeaction, and systemsettingswrite. This allowed attackers to execute the following scripts as root:
- SystemSettingsWrite.py
- AutoAptUpgrade.py
CRLF Injection Vulnerability Allows Configuration Management in Pardus Linux
The second vulnerability in CVE-2026–5140 involved SystemSettingsWrite.py, which writes user-entered data to the configuration file: /etc/pardus/pardus-update.conf
Although ConfigParser "cleans" newline characters (\n), it does not properly filter carriage returns (\r). Attackers could exploit this vulnerability using the following payload: 123\rcustom_sourcesd_path=/tmp/pwn.list
See also: YellowKey BitLocker bypass – Microsoft's mitigations and what IT admins should change
The introduced carriage return caused the parser to interpret the second part as a new configuration entry: custom_sourcesd_path=/tmp/pwn.list
This gave attackers control over the APT source configuration used by the update system.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Malicious Repository Leads to Root Access
The final stage of CVE-2026–5140 targeted AutoAptUpgrade.py, which copied attacker-controlled .list files directly to /etc/apt/sources.list.d/ (without validating the source path).
The researchers demonstrated a proof-of-concept attack by creating a malicious Debian package that modified /bin/bash with the SUID bit via a postinst script: #!/bin/sh chmod +s /bin/bash exit 0
The exploit was activated with two commands:
pkexec /usr/share/pardus/pardus-update/src/SystemSettingsWrite.py write \
lastupgrade $'123\rcustom_sourcesd_path=/tmp/pwn.list'
pkexec /usr/share/pardus/pardus-update/src/AutoAptUpgrade.py
After execution, attackers could obtain a root shell using: /bin/bash -p
See also: Arch Linux: PoC exploit released for PinTheft vulnerability
Researchers confirmed that the attack provided full administrative access, including the ability to read sensitive files, install permanent backdoors, replace system files, and completely take over vulnerable Pardus Linux systems.
The vulnerability was discovered and documented on March 13, 2026 by Çağrı Eser. The researchers advised administrators to immediately strengthen Polkit rules, sanitize CRLF characters in user input, and restrict APT source paths to trusted directories.

The case of CVE-2026–5140 highlights in the clearest way how dangerous a combination of seemingly “minor” security vulnerabilities can become when exploited in a chain by an attacker. While each vulnerability alone might not have directly led to a full breach, the combination of Polkit authorization bypass, CRLF injection, and untrusted search path created an extremely critical exploit chain, capable of granting full root access in a matter of seconds. The incident is yet another reminder that operating system-level security does not depend only on the kernel or software packages, but also on the correct configuration of management tools and privileged services.
At the same time, the fact that Pardus Linux is widely used in government organizations, educational institutions and business environments in Turkey significantly increases the seriousness of the case. System administrators are now urged to immediately proceed with security checks, updates and hardening of access policies, as such vulnerabilities can be an ideal entry point for espionage attacks, malware installation or even complete takeover of critical infrastructure. CVE-2026–5140 also shows that the security of the open-source ecosystem requires continuous auditing and stricter control over the way scripts, services and privilege escalation mechanisms interact with each other.
