📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Higher Education CRITICAL 9h Global data_breach Government HIGH 10h Global supply_chain Software Development and Open Source Communities CRITICAL 10h Global malware Software Development CRITICAL 10h Global phishing Multiple Sectors HIGH 10h Global vulnerability Web Applications CRITICAL 11h Global apt Critical Infrastructure CRITICAL 11h Global ransomware Multiple sectors CRITICAL 11h Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 12h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 13h Global vulnerability Higher Education CRITICAL 9h Global data_breach Government HIGH 10h Global supply_chain Software Development and Open Source Communities CRITICAL 10h Global malware Software Development CRITICAL 10h Global phishing Multiple Sectors HIGH 10h Global vulnerability Web Applications CRITICAL 11h Global apt Critical Infrastructure CRITICAL 11h Global ransomware Multiple sectors CRITICAL 11h Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 12h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 13h Global vulnerability Higher Education CRITICAL 9h Global data_breach Government HIGH 10h Global supply_chain Software Development and Open Source Communities CRITICAL 10h Global malware Software Development CRITICAL 10h Global phishing Multiple Sectors HIGH 10h Global vulnerability Web Applications CRITICAL 11h Global apt Critical Infrastructure CRITICAL 11h Global ransomware Multiple sectors CRITICAL 11h Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 12h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 13h
Vulnerabilities

CVE-2026-5161

High
CWE-59 — Weakness Type
Published: Apr 29, 2026  ·  Modified: May 4, 2026  ·  Source: NVD
CVSS v3
8.8
🔗 NVD Official
📄 Description (English)

Improper link resolution before file access ('link following') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus About allows Symlink Attack.

This issue affects Pardus About: before v1.2.1.

🤖 AI Executive Summary

CVE-2026-5161 is a symlink attack vulnerability in Pardus About (before v1.2.1) that allows attackers to manipulate file access through improper link resolution. With a CVSS score of 8.8, this high-severity vulnerability could enable privilege escalation or unauthorized file access on affected systems. The lack of available patches requires immediate compensating controls and monitoring until vendor remediation is released.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 4, 2026 03:48
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability primarily affects government and public sector organizations in Saudi Arabia that deploy Pardus-based systems. The National Cybersecurity Authority (NCA) and government IT infrastructure using Turkish-origin Pardus distributions are at elevated risk. Potential impact includes unauthorized access to sensitive government data, system compromise, and privilege escalation on critical infrastructure systems. Organizations in the public administration, defense, and critical infrastructure sectors should prioritize assessment and mitigation.
🏢 Affected Saudi Sectors
Government & Public Administration Critical Infrastructure Defense & Security Education (Universities using Pardus) Healthcare (if Pardus-based systems deployed) Telecommunications
⚖️ Saudi Risk Score (AI)
7.8
/ 10.0
🔧 Remediation Steps (English)
Immediate Actions:
1. Inventory all systems running Pardus About and identify versions prior to v1.2.1
2. Restrict file system permissions to prevent symlink creation in sensitive directories
3. Implement strict access controls on /tmp and other world-writable directories
4. Monitor system logs for suspicious symlink creation attempts

Compensating Controls (until patch available):
5. Disable symlink following in Pardus About configuration if available
6. Use mount options (nosymfollow) on critical partitions
7. Implement SELinux or AppArmor policies to restrict symlink operations
8. Run Pardus About with minimal required privileges

Detection Rules:
9. Monitor for symlink creation in /tmp and /var/tmp directories
10. Alert on file access attempts following symlinks to sensitive locations
11. Track failed file access attempts with permission denied errors
12. Patch to v1.2.1 or later immediately upon availability
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. حصر جميع الأنظمة التي تعمل بـ Pardus About وتحديد الإصدارات السابقة للإصدار 1.2.1
2. تقييد أذونات نظام الملفات لمنع إنشاء الروابط الرمزية في الدلائل الحساسة
3. تطبيق ضوابط وصول صارمة على /tmp والدلائل الأخرى القابلة للكتابة من قبل الجميع
4. مراقبة سجلات النظام للكشف عن محاولات إنشاء روابط رمزية مريبة

الضوابط التعويضية (حتى توفر التصحيح):
5. تعطيل متابعة الروابط الرمزية في إعدادات Pardus About إن أمكن
6. استخدام خيارات التثبيت (nosymfollow) على الأقسام الحرجة
7. تطبيق سياسات SELinux أو AppArmor لتقييد عمليات الروابط الرمزية
8. تشغيل Pardus About بأقل امتيازات مطلوبة

قواعد الكشف:
9. مراقبة إنشاء الروابط الرمزية في دلائل /tmp و /var/tmp
10. تنبيه محاولات الوصول إلى الملفات التي تتبع الروابط الرمزية إلى مواقع حساسة
11. تتبع محاولات الوصول الفاشلة إلى الملفات مع أخطاء الإذن المرفوضة
12. التصحيح إلى الإصدار 1.2.1 أو أحدث فور توفره
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.5.1.1 - Access Control Policies ECC 2024 A.5.2.1 - User Registration and Access Rights ECC 2024 A.5.3.1 - Password Management ECC 2024 A.12.2.1 - Change Management ECC 2024 A.12.6.1 - Management of Technical Vulnerabilities
🔵 SAMA CSF
SAMA CSF ID.AM-2 - Software Inventory SAMA CSF PR.AC-1 - Access Control Policy SAMA CSF PR.AC-3 - Access Enforcement SAMA CSF DE.CM-1 - System Monitoring SAMA CSF RS.MI-2 - Incident Response Procedures
🟡 ISO 27001:2022
ISO 27001:2022 A.5.15 - Access Control ISO 27001:2022 A.8.1 - User Endpoint Devices ISO 27001:2022 A.8.3 - Access Control ISO 27001:2022 A.12.6.1 - Management of Technical Vulnerabilities ISO 27001:2022 A.14.2.1 - Secure Development Policy
📊 CVSS Score
8.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionR — Required
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score8.8
CWECWE-59
EPSS0.05%
Exploit No
Patch ✗ No
Published 2026-04-29
Source Feed nvd
🇸🇦 Saudi Risk Score
7.8
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-59
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.