CVE-2026-35535 Details
Description
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
A vulnerability in Sudo versions through 1.9.17p2 has been identified, allowing for local privilege escalation. This issue arises from a failure to properly handle setuid, setgid, or setgroups calls during a privilege drop before executing the mailer. The vulnerability can be exploited by loading a restrictive AppArmor profile that denies Sudo the ability to drop root privileges, causing Sudo to execute commands as root with preserved environment variables. The flaw has been acknowledged and fixed in the official Sudo repository.
Users can update to Sudo versions 1.9.17p2-1ubuntu1.1 or 1.9.15p5-3ubuntu5.24.04.2, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-271 | Privilege Dropping / Lowering Errors | [email protected] |
| CWE-272 | Least Privilege Violation | redhat-SADP |
Affected Products
| Product | Versions |
|---|---|
| sudo project sudo | < 1.9.17 1.9.17 - 1.9.17 p1 1.9.17 p2 |
CPE
Remediation
| |
| siemens sinec os | < 4.0 |
CPE
Remediation
| |
| siemens ruggedcom rst2428p | All versions |
CPE
Remediation
| |
Change History
18 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 1, 2026 | CVE Modified | redhat-SADP |
| Sep 1, 2026 | CVE Modified | siemens-SADP |
| Sep 1, 2026 | CVE Modified | [email protected] |
| Sep 1, 2026 | CVE Modified | CVE |
| Aug 25, 2026 | CVE Modified | redhat-SADP |
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 10, 2026 | CVE Modified | redhat-SADP |
| Jul 2, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | siemens-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2026 | CVE Modified | CVE |
| Jun 2, 2026 | Reanalysis | [email protected] |
| Jun 2, 2026 | Initial Analysis | [email protected] |
| Jun 2, 2026 | CVE Modified | siemens-SADP |
| Apr 3, 2026 | New CVE Received | [email protected] |