CVE-2026-35339 is a logic flaw in the recursive mode of the chmod utility within uutils coreutils where exit codes are incorrectly reported based solely on the last file processed, rather than reflecting overall command success. This defect affects any system using the vulnerable version of uutils coreutils, particularly those relying on chmod's return values in automated scripts or batch operations. The vulnerability carries a MEDIUM severity rating (CVSS 5.5) with a local attack vector and low complexity requirement. An authenticated local user can trigger the flaw without special privileges or user interaction. The primary impact is integrity-related: scripts may incorrectly assume successful permission changes when errors occurred on earlier files, potentially leaving sensitive files with unintended restrictive or incorrect permissions that could enable subsequent privilege escalation or unauthorized access. There is currently no evidence of active exploitation in the wild, no known public exploit code, and minimal community attention, as indicated by the inactive KEV status, near-zero EPSS score, and low FAUCET Risk Score of 33. Organizations should prioritize patching based on their reliance on recursive chmod operations in production automation rather than urgent threat response, though prompt remediation is still recommended given the integrity implications.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 0.6.0CPE match | cpe:2.3:a:uutils:coreutils:*:*:*:*:*:rust:*:* | ||
< 0.6.0CPE matchmatch criteria | cpe:2.3:a:uutils:coreutils:*:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.