Red Hat disclosed CVE-2026-35535, an Important-severity local privilege escalation flaw in sudo caused by failures in setuid, setgid, or setgroups privilege-dropping calls before the mailer is executed. The weakness, tracked as CWE-272, could allow a local user on an affected system to gain elevated privileges. Red Hat assigned the issue a CVSS v3 score of 7.4, while NVD scored it 7.8.
Red Hat released a series of security advisories and updated sudo packages for affected RHEL 6 ELS, RHEL 7 ELS, multiple RHEL 8 streams including 8.6, 8.8, and 8.10 lifecycle and industry-specific channels, and RHEL 10.0 offerings. Published advisories include RHSA-2026:11521, RHSA-2026:13888, RHSA-2026:13892, RHSA-2026:13895, RHSA-2026:13896, and RHSA-2026:14228, with fixed package versions such as 1.9.5p2-1.el8_10.5, 1.9.5p2-1.el8_8.3, 1.9.5p2-1.el8_6.3, 1.8.23-10.el7_9.5, 1.8.6p3-29.el6_10.8, and 1.9.15-8.p5.el10_0.3 released across supported architectures and channels.

Get the actors, campaigns, and ATT&CK mapping behind it.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat lists Red Hat Enterprise Linux 10 as fixed for CVE-2026-35535 through security advisory RHSA-2026:10758. This was the first RHEL product stream identified in the provided references as receiving a fix for the sudo flaw.
Red Hat published CVE-2026-35535 on April 3, 2026, describing an Important-severity local privilege-escalation vulnerability in sudo caused by failed privilege-dropping calls before running the mailer. The flaw could allow a local user to gain elevated access on affected systems.
A Qualys advisory covering CVE-2026-35535 was dated March 10, 2026. Red Hat later referenced this advisory in its CVE record for the sudo privilege-escalation flaw.
Red Hat lists an additional fix for Red Hat Enterprise Linux 10 through RHSA-2026:19067, released on May 19, 2026, for CVE-2026-35535. This indicates a further security erratum for the affected RHEL 10 stream.
On May 6, 2026, Red Hat published several Important advisories addressing CVE-2026-35535 in sudo across more product streams: RHSA-2026:13888 for RHEL 10.0 EUS and related channels, RHSA-2026:13892 for RHEL 8.8 channels, RHSA-2026:13895 for RHEL 7 ELS, RHSA-2026:13896 for RHEL 6 ELS Extension, and RHSA-2026:14228 for RHEL 8.6 channels. These advisories released updated sudo packages for the affected architectures and support offerings.
Red Hat stated that CVE-2026-35535 was addressed in Red Hat Enterprise Linux 9 through security advisory RHSA-2026:12310. This adds RHEL 9 to the affected Red Hat product streams confirmed as receiving a fix for the sudo privilege-escalation flaw.
On April 29, 2026, Red Hat issued RHSA-2026:11521, an Important security advisory for Red Hat Enterprise Linux 8 that fixes CVE-2026-35535 in sudo. Updated packages version 1.9.5p2-1.el8_10.5 were released for x86_64, s390x, ppc64le, and aarch64 platforms, including Extended Life Cycle 8.10 builds.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
10 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.