CVE-2026-18806
HIGHArbitrary Block Device Write via Missing Validation in TÜBİTAK BİLGEM's pardus-image-writer
Title source: cnaDescription
External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality. This issue affects pardus-image-writer: before 0.9.0.
References (1)
Core 1
Core References
Government Resource government-resource
https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0740
Scores
CVSS v3
7.1
EPSS
0.0010
EPSS Percentile
1.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-73
Status
published
Products (2)
TÜBİTAK BİLGEM Software Technologies Research Institute/pardus-image-writer
< 0.9.0
TÜBİTAK BİLGEM Software Technologies Research Institute/pardus-image-writer
< 1.0.4
Published
Aug 04, 2026
Tracked Since
Aug 04, 2026