CVE-2026-35364 is a Time-of-Check to Time-of-Use race condition affecting the mv utility in uutils coreutils during cross-device file operations. The vulnerability exploits a window where the destination path is removed before being recreated, allowing a local attacker with write access to the destination directory to insert a symbolic link that redirects subsequent privileged write operations to arbitrary target files. The vulnerability carries a CVSS score of 6.3 MEDIUM severity with a local attack vector requiring high complexity and low privileges. While confidentiality is not impacted, the vulnerability enables high-integrity and high-availability damage through arbitrary file overwriting, effectively allowing privilege escalation through symlink manipulation. The vulnerability is not currently listed in the Known Exploited Vulnerabilities catalog and shows no evidence of active exploitation in the wild. With an EPSS score of 0.000120000 and a FAUCET risk score of 35.0 out of 100, this represents a low-priority threat with minimal community attention, though organizations using uutils coreutils in privilege-separated environments should monitor for patches and updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE match | cpe:2.3:a:uutils:coreutils:*:*:*:*:*:rust:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:uutils:coreutils:-:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.