---
id: CVE-2026-7863
title: >-
  Improper neutralization of special elements used in an OS command ('OS command
  injection') vulnerability in TUBITAK BILGEM Software Technologies Research
  Institute Pardus Software allows OS Command Injection.


  This issue affects Pardus S…
summary: >-
  Improper neutralization of special elements used in an OS command ('OS command
  injection') vulnerability in TUBITAK BILGEM Software Technologies Research
  Institute Pardus Software allows OS Command Injection.


  This issue affects Pardus S…
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: TUBITAK BILGEM Software Technologies Research Institute
product: Pardus Software
affected:
  - pardus_software < 1.0.5
published: '2026-09-11'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T17:35:21.440'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-7863'
references:
  - url: 'https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1080'
    label: iletisim@usom.gov.tr
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-11T16:22:42.579935Z'
ingestedAt: '2026-09-11T16:45:47.862Z'
epss: 0.00534
epssPercentile: 0.44075
---

## Overview

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software allows OS Command Injection.

This issue affects Pardus Software: before 1.0.5.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
