CVE-2026-102568Medium· 5.5▾ TwilightPoC availablePardus Parental Control before 0.7.0 contains an incorrect authorization vulnerability in the polkit policy that allows unprivileged local users to disable parental controls as root. Attackers can invoke PPCActivator.py with the --disabl…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 30.3 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Exploit / PoC code exists
Pardus Parental Control before 0.7.0 contains an incorrect authorization vulnerability in the polkit policy that allows unprivileged local users to disable parental controls as root. Attackers can invoke PPCActivator.py with the --disable argument via pkexec to remove all restrictions including DNS filtering and application limits without authentication.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-100371High· 8.7InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments
CVE-2026-101139Low· 2.7A vulnerability was detected in Webkul Bagisto up to 2.4.6/2.5.0-beta4
CVE-2026-101056Medium· 5.3Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state from a context_hint UUID
CVE-2026-100721Critical· 9.0vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver
CVE-2026-100623High· 8.8Capgo (capgo.app) exposes the legacy membership table public.org_users directly through Supabase PostgREST
CVE-2026-100628Medium· 4.3capgo.app before 12.128.12 fails to enforce an organization's API key expiration policy when creating app-scoped API keys