CVE-2026-15599
Received Received - Intake

Unverified Ownership Leads to Privilege Abuse in Pardus Domain Joiner

Vulnerability report for CVE-2026-15599, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: Computer Emergency Response Team of the Republic of Turkey

Description

Unverified ownership vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-domain-joiner allows Privilege Abuse. This issue affects pardus-domain-joiner: before 0.5.5.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-18
AI Q&A
2026-08-06
EPSS Evaluated
2026-08-17
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tubitak pardus-domain-joiner to 0.5.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-283 The product does not properly verify that a critical resource is owned by the proper entity.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in TÜBİTAK BİLGEM's pardus-domain-joiner software before version 0.5.5 allows an attacker to exploit unverified ownership, potentially leading to privilege abuse. This means an unauthorized user could gain elevated access or perform actions beyond their intended permissions.

Detection Guidance

This vulnerability involves unverified ownership in pardus-domain-joiner before version 0.5.5. To detect it, check the installed version of pardus-domain-joiner using package managers like apt or dpkg on Debian-based systems. Commands: 'dpkg -l pardus-domain-joiner' or 'apt list --installed pardus-domain-joiner'. If the version is below 0.5.5, the system is vulnerable.

Impact Analysis

If exploited, this vulnerability could allow attackers to gain unauthorized privileges on systems using the affected software. This might lead to data breaches, unauthorized system modifications, or disruption of services. Users should update to version 0.5.5 or later to mitigate this risk.

Compliance Impact

The vulnerability allows privilege abuse in pardus-domain-joiner before version 0.5.5, which could lead to unauthorized access or modifications. This may impact compliance with standards like GDPR or HIPAA by potentially exposing sensitive data or violating integrity requirements. However, specific compliance impacts are not detailed in the provided context.

Mitigation Strategies

Update pardus-domain-joiner to version 0.5.5 or later to address the unverified ownership vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15599. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart