OVERVIEW CVE-2026-35350 is a privilege escalation vulnerability in the cp utility of uutils coreutils that occurs during file copying operations with the -p (preserve) flag. When the utility fails to preserve file ownership through chown operations, it incorrectly applies the source file's mode bits—including setuid and setgid permissions—to the destination file despite the ownership change failure. This behavior deviates from the standard GNU cp implementation and can result in unprivileged users obtaining copies of files with elevated privilege bits intact, potentially violating organizational security policies. SEVERITY The vulnerability carries a CVSS v3.1 score of 6.6 (MEDIUM) with a local attack vector requiring low complexity and low privilege level. The impact profile shows low confidentiality and availability impact but high integrity impact, reflecting the core risk of unauthorized privilege escalation. An authenticated local user could exploit this through normal file copy operations to create unintended privileged executables. The EPSS score of 0.0001 indicates minimal current exploitation activity within the broader threat landscape. EXPLOITATION STATUS There is no indication of active exploitation, as the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and remains inactive on threat intelligence hot lists. No publicly available exploit code has been identified. Community attention appears limited given the narrow scope of the affected utility and the specialized knowledge required to exploit this behavior, though organizations using uutils coreutils should monitor for security updates and implement patching procedures accordingly.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE match | cpe:2.3:a:uutils:coreutils:*:*:*:*:*:rust:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:uutils:coreutils:-:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.