CVE-2026-35535: High severity Microsoft azl3 sudo 1.9.17-1 vulnerability
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Sudoto a version that resolves this vulnerability.Patch 3e474c2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35535?
CVE-2026-35535 is classified as a high severity vulnerability due to its potential to allow privilege escalation.
How do I fix CVE-2026-35535?
To fix CVE-2026-35535, update Sudo to a version that includes patches addressing this vulnerability.
What software is affected by CVE-2026-35535?
CVE-2026-35535 affects Sudo versions before 1.9.17p2.
Can CVE-2026-35535 lead to exploitation?
Yes, CVE-2026-35535 can lead to exploitation by allowing local attackers to escalate privileges.
What is the impact of CVE-2026-35535 on system security?
CVE-2026-35535 impacts system security by potentially enabling unauthorized users to gain elevated privileges.