Junglewise Threat Intelligence

CVE-2026-35535: Sudo privilege escalation via fail-open privilege drop in mailer

CVE-2026-35535 · Severity: high · CVSS 7.4 · Published 2026-04-03

Technologies: Sudo Project Sudo.

Executive brief

A vulnerability in the Sudo utility, a tool used to grant administrative privileges to users, could allow a local attacker to gain full root access to a system. The issue occurs when Sudo fails to properly drop its administrative privileges before running a mail notification program. In certain environments where security policies (like AppArmor) interfere with Sudo's ability to lower its permissions, the tool may continue running with full system authority instead of stopping, leading to a complete system takeover.

Technical details

A privilege escalation vulnerability exists in Sudo's 'exec_mailer' function. When Sudo attempts to drop privileges (via setuid, setgid, or setgroups) before executing a mailer (like sendmail) to notify administrators of security events, it fails to treat a failure of these calls as a fatal error. In a 'fail-open' scenario—specifically demonstrated when an AppArmor profile denies the setuid capability—Sudo continues execution as root instead of terminating. An attacker can exploit this to execute the mailer with unintended elevated privileges. The fix makes these privilege-drop failures fatal and ensures both GID and UID are correctly set.

Affected products

  • Sudo Project Sudo through 1.9.17p2

Timeline

  • 2026-03-02: patched: Initial fix in Ubuntu packages
  • 2026-03-10: disclosed: Qualys 'CrackArmor' advisory published
  • 2026-04-02: advisory: CVE-2026-35535 assigned and NVD record published

References