Sceawere
Vulnerability Detail
CVE-2026-102568UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Pardus Parental Control Authorization Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 10h ago
- Vendor
- pardus
- Product
- pardus-parental-control
- Attack Type
- Incorrect Authorization
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Pardus Parental Control before 0.7.0 contains an incorrect authorization vulnerability in the polkit policy that allows unprivileged local users to disable parental controls as root. Attackers can invoke PPCActivator.py with the --disable argument via pkexec to remove all restrictions including DNS filtering and application limits without authentication.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-09-29T15:17:18.443Z",
"pubdate": "2026-09-29T15:17:18.443Z",
"executiveSummary": "Pardus Parental Control (PPC) versions prior to 0.7.0 are susceptible to an incorrect authorization vulnerability residing within its polkit policy configuration. This flaw allows an unprivileged local user to circumvent security controls by leveraging pkexec to execute administrative scripts. The vulnerability stems from an insecurely configured policy file that permits non-root users to invoke privileged operations without requiring proper authentication or authorization checks. Successful exploitation grants an attacker the ability to disable all parental control features, including DNS-based filtering and application usage restrictions, effectively rendering the security suite ineffective. Because the exploitation occurs locally, the primary risk involves users with direct system access—such as children or unauthorized personnel—bypassing established usage policies. The integrity of the system security boundary is compromised, as the attacker gains the ability to execute arbitrary commands with root privileges through the vulnerable component.",
"technicalDetails": "The vulnerability is localized within the polkit policy configuration of the Pardus Parental Control suite, specifically affecting how the system manages access control for the PPCActivator.py script. The root cause is a misconfigured polkit policy that grants insufficient authorization requirements for the execution of this utility. Under normal operational conditions, polkit is intended to act as a system-wide policy toolkit for defining and handling authorizations; however, the policy associated with Pardus Parental Control incorrectly allows unprivileged local users to trigger the execution of PPCActivator.py via the pkexec binary.\nThe exploitation process follows a predictable flow: an unprivileged local attacker invokes the script PPCActivator.py by passing the --disable argument through the pkexec interface. Because the polkit policy does not mandate a password prompt or group membership verification for this specific action, pkexec grants the script execution context with elevated root privileges. When invoked with the --disable flag, the script proceeds to modify system configurations or terminate background daemons that enforce DNS filtering and application white-listing/black-listing protocols.\nThe attack is characterized by the following requirements and behaviors: First, it requires local access to the system where Pardus Parental Control is deployed. Second, it leverages the legitimate pkexec utility, which is a standard component of polkit, to facilitate the elevation of privilege. Once the script is executed under these conditions, the application limits and network restrictions are removed instantaneously. The impact is significant, as the tool designed to protect the user or manage usage is deactivated, leaving the system in a state where policies are no longer enforced. The vulnerability affects all versions of Pardus Parental Control before 0.7.0. Because this involves local interaction with system configuration files and services, there is no remote network exposure, but the risk to local policy enforcement is absolute."
}