Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35350

22
FAUCET Score

OVERVIEW CVE-2026-35350 is a privilege escalation vulnerability in the cp utility of uutils coreutils that occurs during file copying operations with the -p (preserve) flag. When the utility fails to preserve file ownership through chown operations, it incorrectly applies the source file's mode bits—including setuid and setgid permissions—to the destination file despite the ownership change failure. This behavior deviates from the standard GNU cp implementation and can result in unprivileged users obtaining copies of files with elevated privilege bits intact, potentially violating organizational security policies. SEVERITY The vulnerability carries a CVSS v3.1 score of 6.6 (MEDIUM) with a local attack vector requiring low complexity and low privilege level. The impact profile shows low confidentiality and availability impact but high integrity impact, reflecting the core risk of unauthorized privilege escalation. An authenticated local user could exploit this through normal file copy operations to create unintended privileged executables. The EPSS score of 0.0001 indicates minimal current exploitation activity within the broader threat landscape. EXPLOITATION STATUS There is no indication of active exploitation, as the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and remains inactive on threat intelligence hot lists. No publicly available exploit code has been identified. Community attention appears limited given the narrow scope of the affected utility and the specialized knowledge required to exploit this behavior, though organizations using uutils coreutils should monitor for security updates and implement patching procedures accordingly.

Impacted Technologies

VendorProductVersion(s)CPE
All Versions ImpactedCPE match
cpe:2.3:a:uutils:coreutils:*:*:*:*:*:rust:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:uutils:coreutils:-:*:*:*:*:rust:*:*

CVSS Data

CVSS version used by this source: 3.1

6.6MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
1.8
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.13%
Probability of exploitation in next 30 days
EPSS Percentile
2.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0013 is in the 18th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

rustGHSA-x2wv-9p67-mh9wmedium

uutils coreutils doesn't properly handle setuid and setgid bits when ownership preservation fails

Apr 22, 2026

References

github.com / uutils/coreutils/issues/9750
ExploitIssue TrackingVendor Advisory