---
id: CVE-2026-102568
title: >-
  Pardus Parental Control before 0.7.0 contains an incorrect authorization
  vulnerability in the polkit policy that allows unprivileged local users to
  disable parental controls as root
summary: >-
  Pardus Parental Control before 0.7.0 contains an incorrect authorization
  vulnerability in the polkit policy that allows unprivileged local users to
  disable parental controls as root. Attackers can invoke PPCActivator.py with
  the --disabl…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-863
vendor: pardus
product: pardus-parental-control
affected:
  - pardus-parental-control < 0.7.0
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T15:17:18.443'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102568'
references:
  - url: 'https://github.com/pardus/pardus-parental-control'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/pardus/pardus-parental-control/blob/4045f9513fa2d19ad9dbee25b39acb55a018c58e/polkit/tr.org.pardus.pkexec.parental-control.policy#L9-L21
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/pardus/pardus-parental-control/commit/42d8373b6b8d9bf348e9378fb6ad4a2750d503e7
    label: disclosure@vulncheck.com
  - url: 'https://github.com/pardus/pardus-parental-control/pull/5'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/pardus/pardus-parental-control/releases/tag/debian%2F0.7.0
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/pardus-parental-control-before-0.7.0-incorrect-authorization-via-ppcactivator-py
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
ingestedAt: '2026-09-29T16:39:33.258Z'
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-29T17:31:15.374316Z'
---

## Overview

Pardus Parental Control before 0.7.0 contains an incorrect authorization vulnerability in the polkit policy that allows unprivileged local users to disable parental controls as root. Attackers can invoke PPCActivator.py with the --disable argument via pkexec to remove all restrictions including DNS filtering and application limits without authentication.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
