{"id":"CVE-2026-8304","title":"Information Disclosure in TUBITAK BILGEM's Pardus About","summary":"Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus About allows Exploiting Incorrectly Configured Access Control Security Levels.\n\nThis issue affects Pardus About: from 1.2.1 before 1.2.5.","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cvssSource":"cna","cwe":["CWE-862"],"vendor":"TUBITAK BILGEM Software Technologies Research Institute","product":"Pardus About","affected":["pardus_about >= 1.2.1 < 1.2.5"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-11T19:16:00.543992Z"},"published":"2026-09-11","updated":"2026-09-11","sourceUpdated":"2026-09-11T19:16:13.556Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-8304","references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1082"}],"tags":["cve.org"],"epss":0.00097,"epssPercentile":0.00834,"ingestedAt":"2026-09-14T00:35:28.535Z","slug":"CVE-2026-8304","body":"## Overview\n\nMissing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus About allows Exploiting Incorrectly Configured Access Control Security Levels.\n\nThis issue affects Pardus About: from 1.2.1 before 1.2.5.\n\n## Affected\n\n- `pardus_about >= 1.2.1 < 1.2.5`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}