Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35535

31
FAUCET Score

CVE-2026-35535 is a privilege escalation vulnerability in Sudo versions through 1.9.17p2, stemming from a non-fatal error when privilege-dropping calls (setuid, setgid, setgroups) fail before running the mailer. Rated High with a CVSS score of 7.4, this vulnerability allows for high impact to confidentiality, integrity, and availability, though it requires local access and has high attack complexity. There is currently no evidence of active exploitation, nor are public exploit modules available on platforms like Metasploit or ExploitDB. Community discussion and media coverage remain low, indicating limited public attention at this time.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.9.17CPE matchmatch criteria
cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:*
1.9.17CPE matchmatch criteria
cpe:2.3:a:sudo_project:sudo:1.9.17:-:*:*:*:*:*:*
1.9.17CPE matchmatch criteria
cpe:2.3:a:sudo_project:sudo:1.9.17:p1:*:*:*:*:*:*
1.9.17CPE matchmatch criteria
cpe:2.3:a:sudo_project:sudo:1.9.17:p2:*:*:*:*:*:*
< 4.0CPE matchmatch criteria
cpe:2.3:o:siemens:sinec_os:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.4HIGH

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.4
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.17%
Probability of exploitation in next 30 days
EPSS Percentile
7.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0017 is in the 29th percentile among its peer group of 16,994 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: 20260-17086Fixed in: 1.9.17-2
microsoftpatch availablevia msrc
Product: cbl2 sudo 1.9.17-1 on CBL Mariner 2.0Fixed in: 1.9.17-2
microsoftpatch availablevia msrc
Product: azl3 sudo 1.9.17-1 on Azure Linux 3.0Fixed in: 1.9.17-2
microsoftpatch availablevia msrc
Product: 19595-17084Fixed in: 1.9.17-2

Vendor Advisories (1)

microsoft2026-Apr/CVE-2026-35535Important

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

Apr 2, 2026

References

access.redhat.com / errata/RHSA-2026:10758
access.redhat.com / errata/RHSA-2026:11521
access.redhat.com / errata/RHSA-2026:12310
access.redhat.com / errata/RHSA-2026:13731
access.redhat.com / errata/RHSA-2026:13888
access.redhat.com / errata/RHSA-2026:13889
access.redhat.com / errata/RHSA-2026:13891
access.redhat.com / errata/RHSA-2026:13892
access.redhat.com / errata/RHSA-2026:13895
access.redhat.com / errata/RHSA-2026:13896
access.redhat.com / errata/RHSA-2026:14228
access.redhat.com / errata/RHSA-2026:14437
access.redhat.com / errata/RHSA-2026:19067
access.redhat.com / errata/RHSA-2026:19220
access.redhat.com / errata/RHSA-2026:20040
access.redhat.com / errata/RHSA-2026:20087
access.redhat.com / errata/RHSA-2026:21275
access.redhat.com / errata/RHSA-2026:21656
access.redhat.com / errata/RHSA-2026:21690
access.redhat.com / errata/RHSA-2026:21695
access.redhat.com / errata/RHSA-2026:23233
access.redhat.com / errata/RHSA-2026:28887
access.redhat.com / errata/RHSA-2026:30088
access.redhat.com / errata/RHSA-2026:34098
access.redhat.com / security/cve/CVE-2026-35535
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-35535.json
cert-portal.siemens.com / productcert/html/ssa-253495.html
Third Party Advisory
lists.debian.org / debian-lts-announce/2026/06/msg00003.html
bugs.debian.org / 1130593
Broken Link
bugs.launchpad.net / ubuntu/+source/sudo/+bug/2143042
Issue Tracking
github.com / sudo-project/sudo/commit/3e474c2f201484be83d994ae10a4e20e8c81bb69
Patch
qualys.com / 2026/03/10/crack-armor.txt
Third Party Advisory