CVE-2026-35535
published 2026-04-03CVE-2026-35535: In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.17%
7.0th percentile
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sudo | < sudo 1.9.17p2-5 (forky) | sudo 1.9.17p2-5 (forky) |
| msrc | azl3_sudo_1.9.17-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_sudo_1.9.17-1_on_cbl_mariner_2.0 | — | — |
| siemens | sinec_os | < 4.0 | 4.0 |
| sudo_project | sudo | < 3e474c2f201484be83d994ae10a4e20e8c81bb69 | 3e474c2f201484be83d994ae10a4e20e8c81bb69 |
| sudo_project | sudo | < 1.9.17 | 1.9.17 |
| sudo_project | sudo | — | — |
| sudo_project | sudo | — | — |
| sudo_project | sudo | — | — |
| sudo_project | sudo | >= 0 < 1.9.17p2-5 | 1.9.17p2-5 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.4HIGH
vendor_debian7.4HIGH
vendor_msrc7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
sudo: Sudo: Privilege escalation due to failure in privilege drop calls
vendor_redhat·2026-04-03·CVSS 7.4
CVE-2026-35535 [HIGH] CWE-272 sudo: Sudo: Privilege escalation due to failure in privilege drop calls
sudo: Sudo: Privilege escalation due to failure in privilege drop calls
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
A flaw was found in Sudo. A local user could exploit a failure in the setuid, setgid, or setgroups calls, which are used to drop privileges before running the mailer. This oversight allows for privilege escalation, enabling the user to gain elevated access on the system.
Package: sudo (Red Hat Enterprise Linux 10) - Affected
Package: sudo (Red Hat Enterprise Linux 6) - Affected
Package: sudo (Red Hat Enterprise Linux 7) - Affected
Package: sudo (Red Hat Enterprise Linux 8) - Affected
Package: sudo (Red Hat Enterpri
Microsoft
CVE-2026-35535: Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
vendor_msrc·2026-04-02·CVSS 7.4
CVE-2026-35535 [HIGH] CWE-271 CVE-2026-35535: Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Debian
CVE-2026-35535: sudo - In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgr...
vendor_debian·2026·CVSS 7.4
CVE-2026-35535 [HIGH] CVE-2026-35535: sudo - In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgr...
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.9.17p2-5)
sid: resolved (fixed in 1.9.17p2-5)
trixie: open
OSV
CVE-2026-35535: In Sudo through 1
osv·2026-04-03·CVSS 7.4
CVE-2026-35535 [HIGH] CVE-2026-35535: In Sudo through 1
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
GHSA
GHSA-g5fc-f834-rcr2: In Sudo through 1
ghsa_unreviewed·2026-04-03
CVE-2026-35535 [HIGH] CWE-271 GHSA-g5fc-f834-rcr2: In Sudo through 1
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-35535 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-35535 [MEDIUM] CVE-2026-35535 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-35535 :
Linux Debian vulnerability analysis and mitigation
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
Source : NVD
## 7.4
Score
Published April 3, 2026
Severity HIGH
CNA Score 7.4
Affected Technologies
Linux Debian
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
seal-sudo
sudo
Sources
NVD
Debian 11 Severity HIGH No Fix Added at: Apr 03, 2026
Debian 12, 13 Severity MEDIUM No Fix Added at: Apr 03, 2026
Debian 14 Severity HIGH H
Bugzilla
CVE-2026-35535 sudo: Sudo: Privilege escalation due to failure in privilege drop calls
bugzilla·2026-04-03·CVSS 7.4
CVE-2026-35535 [HIGH] CVE-2026-35535 sudo: Sudo: Privilege escalation due to failure in privilege drop calls
CVE-2026-35535 sudo: Sudo: Privilege escalation due to failure in privilege drop calls
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:10758 https://access.redhat.com/errata/RHSA-2026:10758
https://bugs.debian.org/1130593https://bugs.launchpad.net/ubuntu/+source/sudo/+bug/2143042https://github.com/sudo-project/sudo/commit/3e474c2f201484be83d994ae10a4e20e8c81bb69https://www.qualys.com/2026/03/10/crack-armor.txthttps://lists.debian.org/debian-lts-announce/2026/06/msg00003.htmlhttps://access.redhat.com/errata/RHSA-2026:10758https://access.redhat.com/errata/RHSA-2026:11521https://access.redhat.com/errata/RHSA-2026:12310https://access.redhat.com/errata/RHSA-2026:13731https://access.redhat.com/errata/RHSA-2026:13888https://access.redhat.com/errata/RHSA-2026:13889https://access.redhat.com/errata/RHSA-2026:13891https://access.redhat.com/errata/RHSA-2026:13892https://access.redhat.com/errata/RHSA-2026:13895https://access.redhat.com/errata/RHSA-2026:13896https://access.redhat.com/errata/RHSA-2026:14228https://access.redhat.com/errata/RHSA-2026:14437https://access.redhat.com/errata/RHSA-2026:19067https://access.redhat.com/errata/RHSA-2026:19220https://access.redhat.com/errata/RHSA-2026:20040https://access.redhat.com/errata/RHSA-2026:20087https://access.redhat.com/errata/RHSA-2026:21275https://access.redhat.com/errata/RHSA-2026:21656https://access.redhat.com/errata/RHSA-2026:21690https://access.redhat.com/errata/RHSA-2026:21695https://access.redhat.com/errata/RHSA-2026:23233https://access.redhat.com/errata/RHSA-2026:28887https://access.redhat.com/errata/RHSA-2026:30088https://access.redhat.com/errata/RHSA-2026:34098https://access.redhat.com/security/cve/CVE-2026-35535https://bugzilla.redhat.com/show_bug.cgi?id=2454714https://cert-portal.siemens.com/productcert/html/ssa-253495.htmlhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35535.json
2026-04-03
Published