CVE-2026-9085: DNS Spoofing via Pardus-Parental-Control Permission Flaw (CVSS 8.8)
CVE-2026-9085 is a permission and access control flaw in Pardus-Parental-Control (version 0.5.1 and earlier) that allows a local attacker to perform DNS spoofing attacks. Because the software incorrectly assigns permissions to security-critical resources, an attacker with basic local user access can manipulate DNS resolution on the affected system, redirecting network traffic to malicious destinations. This is particularly concerning in environments where Pardus-Parental-Control is deployed to manage network access or security policies.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 8.8 HIGH · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-284, CWE-732
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-07-05 / 2026-07-06
NVD description (verbatim)
Incorrect Permission Assignment for Critical Resource, Improper Access Control vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-Parental-Control allows DNS Spoofing. This issue affects Pardus-Parental-Control: from <=0.5.1 before 0.7.0.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The vulnerability stems from improper permission assignment (CWE-284, CWE-732) on critical DNS control resources within Pardus-Parental-Control. A local, unprivileged attacker can exploit weak access controls to gain the ability to spoof DNS responses, effectively hijacking name resolution for the affected host or potentially connected systems. The attack requires local system access but no special privileges or user interaction. The CVSS 3.1 score of 8.8 (HIGH) reflects the combination of local attack vector with high impact across confidentiality, integrity, and availability, and the potential for scope change indicating cross-boundary compromise.
Business impact
DNS spoofing from this vulnerability can enable credential harvesting, phishing attacks, malware distribution, and session hijacking. If Pardus-Parental-Control is deployed in educational institutions, corporate environments, or managed service provider networks, a single compromised low-privilege user account becomes a pivot point to redirect traffic organization-wide. Organizations may face data exfiltration, unauthorized access to internal services, or deployment of backdoors without detection.
Affected systems
Pardus-Parental-Control version 0.5.1 and all earlier versions are vulnerable. The software is maintained by TUBITAK BILGEM Software Technologies Research Institute. Affected deployments are most likely in Turkish government, education, and enterprise environments where Pardus (a Linux distribution and associated tools) is in use. Systems running patched versions 0.7.0 and later are not affected.
Exploitability
Exploitation requires local system access but no elevated privileges. An attacker needs only standard user credentials to trigger the DNS spoofing capability. No user interaction, network complexity, or exploitation chain is required once local access is obtained. This makes it a high-risk vector in multi-tenant environments, shared systems, or after credential compromise. The vulnerability is not known to be publicly exploited at present, but the simplicity of the attack surface means working exploits are likely straightforward to develop.
Remediation
Update Pardus-Parental-Control to version 0.7.0 or later. Verify the update through official TUBITAK BILGEM channels or your distribution repository. After patching, validate that DNS resolution is functioning correctly and that local user permissions on DNS control resources have been properly restricted. Organizations unable to patch immediately should restrict local user access to affected systems and monitor DNS query patterns for anomalies.
Patch guidance
Obtain version 0.7.0 or later from TUBITAK BILGEM's official repository or your Linux distribution provider. Verify the package signature and integrity before installation. Test the patch in a non-production environment first, especially if Pardus-Parental-Control is integrated with centralized DNS or network monitoring systems. After deployment, confirm that parental controls and DNS filtering policies still function as expected. Document the update and verify that no local user accounts retain elevated DNS manipulation capabilities post-patch.
Detection guidance
Monitor for unauthorized DNS configuration changes by low-privilege users. Look for processes spawned by standard user accounts that interact with DNS sockets, nameserver configuration files, or system resolver libraries. Check file permissions on /etc/resolv.conf, nameserver configuration directories, and any Pardus-Parental-Control control sockets. Implement filesystem auditing (auditd) on DNS-related resources to detect permission escalation attempts. Review access logs for local user sessions accessing DNS control mechanisms, particularly out-of-band from expected parental control management activities.
Why prioritize this
This vulnerability merits immediate attention due to its HIGH CVSS score (8.8), low attack complexity, and high impact across confidentiality, integrity, and availability. The local-only attack vector is mitigated by the prevalence of low-privilege account compromises and insider threats. Organizations relying on Pardus-Parental-Control for DNS filtering or content policy enforcement should prioritize patching, as DNS spoofing directly undermines those controls.
Risk score, explained
CVSS 3.1 score of 8.8 reflects: (1) local attack vector (AV:L) with low attack complexity (AC:L), reducing the skill required to exploit; (2) low privilege requirement (PR:L), meaning standard user credentials suffice; (3) no user interaction needed (UI:N); (4) scope change (S:C), indicating the vulnerability can affect other security domains beyond the vulnerable component; (5) high impact across confidentiality (C:H), integrity (I:H), and availability (A:H), as the attacker can intercept, modify, or deny DNS traffic. The scope change is particularly significant, elevating the score from a lower range to HIGH severity.
Frequently asked questions
Does this vulnerability affect the main Pardus Linux distribution or only the Pardus-Parental-Control add-on?
Only Pardus-Parental-Control is affected. The base Pardus distribution itself does not contain this flaw. However, any system running Pardus-Parental-Control version 0.5.1 or earlier is vulnerable.
Can an attacker exploit this without first gaining local system access?
No. The vulnerability requires local system access and a low-privilege user account. It cannot be exploited remotely over the network. However, local access can be obtained through weak passwords, credential reuse, supply chain compromises, or insider activity.
If we restrict SSH access or disable local login, does this vulnerability become non-exploitable?
Substantially reducing the attack surface. However, other local access vectors—such as physical access, container escape, or process-level privilege issues—could still enable exploitation. Patching remains the definitive fix.
How can we verify that our patch was applied correctly and the vulnerability is truly remediated?
Check that Pardus-Parental-Control version is 0.7.0 or later (via rpm -q or dpkg -l). Audit file permissions on DNS control resources to ensure low-privilege users no longer hold write or execute permissions. Run a filesystem integrity check if your organization uses one, and verify DNS functionality through normal parental control operations.
This analysis is provided for informational purposes and reflects publicly available information as of the publication date. Organizations should verify all technical details against official vendor advisories and their own security testing before making remediation decisions. SEC.co makes no warranty regarding patch availability, compatibility, or effectiveness in specific environments. This vulnerability has not been confirmed to be actively exploited in the wild, but organizations should not delay patching. Always test security updates in non-production environments first. Source: NVD (public-domain), retrieved 2026-08-14. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2021-4480HIGHDräger Protector Software Local Privilege Escalation Vulnerability
- CVE-2021-4481HIGHDräger Protector Software Local Privilege Escalation Vulnerability
- CVE-2025-22426HIGHAndroid ComputerEngine URI Escalation Privilege Vulnerability
- CVE-2025-45422HIGHProximus b-box v8c.725A Access Control Flaw Allows Unauthorized Port Forwarding Changes
- CVE-2025-46315HIGHmacOS Tahoe Permissions Flaw Enables Unauthorized Data Access
- CVE-2025-63579HIGHKyocera TASKalfa Printer Authentication Bypass & Credential Extraction
- CVE-2025-66391HIGHCitrix Cloud Read-Only Account Privilege Escalation to Account Takeover
- CVE-2025-71380HIGHn8n Execute Command Node Arbitrary Command Execution Vulnerability