CVE-2026-35535 PUBLISHED

Assigner: mitre
Reserved: 03.04.2026 Published: 03.04.2026 Updated: 03.04.2026

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.4

Product Status

Vendor Sudo project
Product Sudo
Versions Default: unaffected
  • affected from 0 to 3e474c2f201484be83d994ae10a4e20e8c81bb69 (excl.)

References

Problem Types

  • CWE-271 Privilege Dropping / Lowering Errors CWE