What is CVE-2026-18806?
An external control of file name or path vulnerability (CVE-2026-18806) in TÜBİTAK BİLGEM's pardus-image-writer allows attackers to remove important client functionality. This affects versions before 1.0.4, and users should urgently update to the latest version to mitigate the risk.
Azərbaycanca: TÜBİTAK BİLGEM-in pardus-image-writer proqramında kritik fayl adı və ya yolu idarəetmə zəifliyi (CVE-2026-18806) aşkarlanıb. Bu zəiflik uzaqdan müdaxilə edən şəxsə vacib müştəri funksionallığını silməyə imkan verir. Təsirə məruz qalan istifadəçilər dərhal 1.0.4 və daha yuxarı versiyaya yeniləmə etməlidirlər.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which software is affected by CVE-2026-18806 and what versions are at risk?
This vulnerability affects TÜBİTAK BİLGEM's pardus-image-writer versions before 1.0.4.
What does CVE-2026-18806 allow a remote attacker to do?
This external control of file name or path vulnerability allows a remote attacker to remove important client functionality.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.