HomeSecurityPardus Linux: Chain of vulnerabilities allows complete system takeover

Pardus Linux: Chain of vulnerabilities allows complete system takeover

A chain of local privilege escalation vulnerabilities, codenamed CVE-2026–5140, has exposed serious security flaws in Pardus Linux. Researchers have revealed that the flaws allow any unprivileged local user to gain full root access without authentication, potentially leading to a complete system compromise within seconds. The vulnerability affects the pardus-update, which manages system updates via graphical tools and privileged Python helper scripts. The issue has received a CVSS v3.1 score of 9.3/10, classifying it as “Critical.”

Pardus Linux

The published vector is: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Pardus Linux, which is maintained by TÜBİTAK, is widely used in Turkish government institutions, schools, and business environments. The researchers said the attack chain behind CVE-2026–5140 combines three separate vulnerabilities: a Polkit authorization bypass, a CRLF injection vulnerability, and an untrusted search path issue.

See also: Drupal Core vulnerability allows RCE attacks on PostgreSQL sites

Polkit Misconfiguration Opens the Door for Attack

The first issue was detected in the file: /usr/share/polkit-1/actions/tr.org.pardus.pkexec.pardus-update.policy

The researchers discovered that several privileged actions were configured with unchecked access rights :

<defaults>
 <allow_any>yes</allow_any>
 <allow_inactive>yes</allow_inactive>
 <allow_active>yes</allow_active>
</defaults> 

Because of this configuration, any local user could perform privileged operations via pkexec without entering an administrator password.

The vulnerable actions included aptupdateaction, autoaptupgradeaction, and systemsettingswrite. This allowed attackers to execute the following scripts as root:

  • SystemSettingsWrite.py  
  • AutoAptUpgrade.py 

CRLF Injection Vulnerability Allows Configuration Management in Pardus Linux

The second vulnerability in CVE-2026–5140 involved SystemSettingsWrite.py, which writes user-entered data to the configuration file: /etc/pardus/pardus-update.conf

Although ConfigParser "cleans" newline characters (\n), it does not properly filter carriage returns (\r). Attackers could exploit this vulnerability using the following payload: 123\rcustom_sourcesd_path=/tmp/pwn.list

See also: YellowKey BitLocker bypass – Microsoft's mitigations and what IT admins should change

The introduced carriage return caused the parser to interpret the second part as a new configuration entry: custom_sourcesd_path=/tmp/pwn.list

This gave attackers control over the APT source configuration used by the update system.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Pardus Linux: Chain of vulnerabilities allows complete system takeover

Malicious Repository Leads to Root Access

The final stage of CVE-2026–5140 targeted AutoAptUpgrade.py, which copied attacker-controlled .list files directly to /etc/apt/sources.list.d/ (without validating the source path).

The researchers demonstrated a proof-of-concept attack by creating a malicious Debian package that modified /bin/bash with the SUID bit via a postinst script: #!/bin/sh chmod +s /bin/bash exit 0

The exploit was activated with two commands:

pkexec /usr/share/pardus/pardus-update/src/SystemSettingsWrite.py write \
lastupgrade $'123\rcustom_sourcesd_path=/tmp/pwn.list' 

pkexec /usr/share/pardus/pardus-update/src/AutoAptUpgrade.py 

After execution, attackers could obtain a root shell using: /bin/bash -p

See also: Arch Linux: PoC exploit released for PinTheft vulnerability

Researchers confirmed that the attack provided full administrative access, including the ability to read sensitive files, install permanent backdoors, replace system files, and completely take over vulnerable Pardus Linux systems.

The vulnerability was discovered and documented on March 13, 2026 by Çağrı Eser. The researchers advised administrators to immediately strengthen Polkit rules, sanitize CRLF characters in user input, and restrict APT source paths to trusted directories.

Pardus Linux: Chain of vulnerabilities allows complete system takeover

The case of CVE-2026–5140 highlights in the clearest way how dangerous a combination of seemingly “minor” security vulnerabilities can become when exploited in a chain by an attacker. While each vulnerability alone might not have directly led to a full breach, the combination of Polkit authorization bypass, CRLF injection, and untrusted search path created an extremely critical exploit chain, capable of granting full root access in a matter of seconds. The incident is yet another reminder that operating system-level security does not depend only on the kernel or software packages, but also on the correct configuration of management tools and privileged services.

At the same time, the fact that Pardus Linux is widely used in government organizations, educational institutions and business environments in Turkey significantly increases the seriousness of the case. System administrators are now urged to immediately proceed with security checks, updates and hardening of access policies, as such vulnerabilities can be an ideal entry point for espionage attacks, malware installation or even complete takeover of critical infrastructure. CVE-2026–5140 also shows that the security of the open-source ecosystem requires continuous auditing and stricter control over the way scripts, services and privilege escalation mechanisms interact with each other.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS