CVE-2026-6849HIGH 8.8EPSS p58.5%

CVE-2026-6849CVE-2026-6849

Description

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus OS My Computer allows OS Command Injection. This issue affects Pardus OS My Computer: from <=0.7.5 before 0.8.0.

Scoring

CVSS 3.18.8 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS1.01% probability of exploitation · percentile 58.5% · 2026-06-19T12:03:05Z
Published2026-04-29
Last modified2026-06-06

Underlying weaknesses· 1

CWE-78

References

  1. https://www.usom.gov.tr/bildirim/tr-26-0131

1

TypeTargetConfidenceTier
WeaknessImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection')cwe-780%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2024-12970
CVE
CVE-2026-5141
CVE
CVE-2026-5140
CVE
CVE-2026-5166
CVE
CVE-2026-5161
CVE
CVE-2025-25067
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.