CVE-2026-35535
CVE-2026-35535 Vulnerability Analysis & Exploit Intelligence
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
Published Updated Sources: cvelistV5, mitre
Triage
Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.
Exploitation
Unreported
no source claims exploitation
EPSS
0%
chance of exploitation in 30 days
CVSS base
7.4
HIGH
CISA SSVC assessment
Three decision points CISA publishes for the CVEs it assesses · SSVC 2.0.3. A stakeholder decision, not a severity score.
Exploitation
None
none · proof-of-concept · active
Automatable
No
can an attacker script all four kill-chain steps
Technical impact
Total
partial · total control of the vulnerable component
Affected scope
The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.
Vendors (3)
Products (27)
Every base score collected
Sources score independently and disagree; each row says who scored it and under which version.
| Score | Version | Severity | Expl. | Impact | Source |
|---|---|---|---|---|---|
| 7.4 | CVSS 3.1 | HIGH | — | — | cvelistV5 |
Weakness & attack patterns
- CWE-271
- CWE-272
Attack patterns reported against this CVE. The ATT&CK techniques below are inferred from its weakness class.
- T1574.005Hijack Execution Flow: Executable Installer File Permissions Weakness
- T1574.010Hijack Execution Flow: Services File Permissions Weakness
- T1027.006Obfuscated Files or Information: HTML Smuggling
References
25 on the record
- github.com/sudo-project/sudo/commit/3e474c2f201484be83d994ae10a4e20e8c81bb69
reference
- www.qualys.com/2026/03/10/crack-armor.txt
reference
- bugs.launchpad.net/ubuntu/+source/sudo/+bug/2143042
reference
- bugs.debian.org/1130593
reference
- cert-portal.siemens.com/productcert/html/ssa-253495.html
reference
- lists.debian.org/debian-lts-announce/2026/06/msg00003.html
reference
- access.redhat.com/security/cve/CVE-2026-35535
vdb-entry, x_refsource_REDHAT
- bugzilla.redhat.com/show_bug.cgi?id=2454714
issue-tracking, x_refsource_REDHAT
Elsewhere on this site
- sudo projectevery CVE for this vendor
- siemensevery CVE for this vendor
- redhatevery CVE for this vendor
- CWE-271other pages naming this weakness
Not in any source we poll
Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.
- No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
- No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
- No exploit packet captures, log samples, or incident case IDs supplied.