TCH HUM KE Kerem Kaan Dasmaz Missing Authorization in Pardus Software Center: Any Local User Can Run APT Update as Root |… A Polkit action shipped with allow_any=yes lets any local user — in no special group, with no password — run a privileged APT-update helper…
TCH KE Kerem Kaan Dasmaz Local Privilege Escalation in Pardus Software Center via APT Option Injection | CVE-2026–14459 A member of the pardus-software group — with no sudo rights and no password — can inject APT options into a privileged helper and execute…
TCH NU NullSecurityX Local Privilege Escalation in Pardus Linux: How Three Bugs Chain Into a Full Root Shell |… A Critical (CVSS 9.3) vulnerability chain in the Pardus update system allows any unprivileged user to silently obtain root access — no…