CVE-2026-35367 is a permission configuration vulnerability in the nohup utility of uutils coreutils, where the default nohup.out output file is created with world-readable permissions (0644) instead of the secure owner-only permissions (0600) implemented by GNU coreutils. This affects multi-user systems where any local user can read the captured stdout/stderr output of commands executed by other users, potentially exposing sensitive information. The vulnerability represents a deviation from established security practices in the widely-deployed GNU coreutils implementation. The vulnerability requires local access to exploit, making the attack vector local with low complexity and low privilege requirements. The impact is limited to confidentiality, with only a low severity CVSS score of 3.3. The EPSS score of 0.0001 indicates minimal real-world exploitation likelihood compared to other vulnerabilities. There is no evidence of active exploitation at this time. The vulnerability does not appear on the KEV catalog, is not listed as a hot topic in security communities, and exploit code availability has not been reported. While this appears to be a low-priority issue from an operational perspective, the permission misconfiguration should still be remediated in environments handling sensitive data through nohup operations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE match | cpe:2.3:a:uutils:coreutils:*:*:*:*:*:rust:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:uutils:coreutils:-:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.