boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-35535

Sudo project Sudo — In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mai…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0018    6.8     —
AFFECTED
  Product  Versions     Fixed
  Sudo     unspecified  —
TIMELINE
  Apr 3   Reserved by mitre
  Apr 3   Published (CNA: mitre)
  Aug 25  RESCORED — CVE-2026-35535 (Sudo project Sudo). CVSS 7.4 → 7.8 (NVD).
CWE-271, CWE-272 · CNA: mitre · CVSS v3.1 · 34 references · NVD status: Modified

Description

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
April 3, 2026ReservedReserved by mitre
April 3, 2026PublishedPublished (CNA: mitre)
August 25, 2026RESCOREDRESCORED — CVE-2026-35535 (Sudo project Sudo). CVSS 7.4 → 7.8 (NVD).

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
Sudo projectSudo———

Weaknesses

CWE-271 · CWE-272

References (34)

Related

Authoritative record: CVE-2026-35535 at cve.org

Vendors: sudo project

Weaknesses: CWE-271 · CWE-272

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-35535 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.