Sploitus

CVE-2026-35535

No indexed exploits for CVE-2026-35535 yet

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

Affected products
Red Os, Rocky Linux, Sudo
Sudo Project Sudo
< 1.9.17
Fix
Available
CVSS 3.1
7.8 HIGH
EPSS
0.2% (7th percentile)
Weakness
CWE-272, CWE-271
NVD status
Modified
Published
2026-04-03
CVE-2026-35535 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-35535 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-35535 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.