CVE-2026-9085
Received Received - Intake

Incorrect Permission Assignment in Pardus-Parental-Control Leads to DNS Spoofing

Vulnerability report for CVE-2026-9085, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-05

Last updated on: 2026-07-05

Assigner: Computer Emergency Response Team of the Republic of Turkey

Description

Incorrect Permission Assignment for Critical Resource, Improper Access Control vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-Parental-Control allows DNS Spoofing. This issue affects Pardus-Parental-Control: from <=0.5.1 before 0.7.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-05
Last Modified
2026-07-05
Generated
2026-07-05
AI Q&A
2026-07-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tubitak_bilgem pardus-parental-control From 0.5.1 (inc) to 0.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-732 The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Incorrect Permission Assignment for a Critical Resource and Improper Access Control issue in the Pardus-Parental-Control software developed by TUBITAK BILGEM Software Technologies Research Institute. It allows an attacker to perform DNS Spoofing by exploiting improper permissions and access controls.

Impact Analysis

The vulnerability can have a severe impact as it allows DNS Spoofing, which can lead to an attacker redirecting network traffic to malicious sites. This can result in the compromise of confidentiality, integrity, and availability of data and systems.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9085. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart