CVE-2026-35341 is a permission modification vulnerability in uutils coreutils mkfifo that occurs when the command attempts to create a FIFO on a path where a file already exists. Rather than properly terminating the operation, mkfifo proceeds to execute a follow-up permissions call on the existing file, potentially changing sensitive file permissions to world-readable mode (644 after umask). This could expose critical files such as SSH private keys to unauthorized access by other local users on the system. The vulnerability carries a CVSS severity score of 7.1 (HIGH) with a local attack vector requiring low privileges and no user interaction. The attack has high impact on both confidentiality and integrity, though availability is not affected. An attacker with local user privileges can exploit this through standard use of the mkfifo utility without special configuration or complexity. The vulnerability is not currently listed on the Known Exploited Vulnerabilities catalog and shows no signs of active exploitation in the wild. No publicly available exploit code has been identified. However, the low EPSS percentile (0.000090000) combined with the straightforward exploitation method and moderate FAUCET risk score of 37.0 suggests this should be monitored for community activity and patched as part of routine vulnerability management cycles.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE match | cpe:2.3:a:uutils:coreutils:*:*:*:*:*:rust:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:uutils:coreutils:-:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.