---
id: CVE-2026-8301
title: >-
  Improper neutralization of special elements used in an OS command ('OS command
  injection') vulnerability in TUBITAK BILGEM Software Technologies Research
  Institute Pardus Boot Repair allows OS Command Injection.


  This issue affects Pardu…
summary: >-
  Improper neutralization of special elements used in an OS command ('OS command
  injection') vulnerability in TUBITAK BILGEM Software Technologies Research
  Institute Pardus Boot Repair allows OS Command Injection.


  This issue affects Pardu…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: TUBITAK BILGEM Software Technologies Research Institute
product: Pardus Boot Repair
affected:
  - pardus_boot_repair < 1.0.8
published: '2026-09-11'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T17:35:21.440'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-8301'
references:
  - url: 'https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1081'
    label: iletisim@usom.gov.tr
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-11T15:01:28.368958Z'
ingestedAt: '2026-09-11T16:45:47.862Z'
epss: 0.00481
epssPercentile: 0.40646
---

## Overview

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection.

This issue affects Pardus Boot Repair: before 1.0.8.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
