CVE-2026-35535High· 7.4▾ TwilightIn Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
sudo < 1.9.17sudo = 1.9.17sinec_os < 4.0Upgrade past the affected range:
sudo 1.9.17sinec_os 4.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55226Medium· 5.4Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations
CVE-2026-79693Low· 3.4Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Least Privilege Violation vulnerability
CVE-2026-79944Low· 3.4Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Least Privilege Violation vulnerability
CVE-2025-47809High· 8.2Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot)
CVE-2026-15271High· 7.5A security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 up to 20260906
CVE-2026-15270High· 7.5A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207