Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 04 Apr 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Privilege Escalation via Non‑fatal Group Privilege Drop in Sudo | sudo: Sudo: Privilege escalation due to failure in privilege drop calls |
| Weaknesses | CWE-272 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 03 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Privilege Escalation via Non‑fatal Group Privilege Drop in Sudo | |
| First Time appeared |
Sudo Project
Sudo Project sudo |
|
| Vendors & Products |
Sudo Project
Sudo Project sudo |
Fri, 03 Apr 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation. | |
| Weaknesses | CWE-271 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-04T03:55:19.379Z
Reserved: 2026-04-03T02:21:32.829Z
Link: CVE-2026-35535
Updated: 2026-04-03T13:14:56.484Z
Status : Awaiting Analysis
Published: 2026-04-03T03:16:18.233
Modified: 2026-04-03T16:10:23.730
Link: CVE-2026-35535
OpenCVE Enrichment
Updated: 2026-04-07T07:55:13Z