Unauthorized File Permission Modification in uutils Coreutils
CVE-2026-35341

7.1HIGH

Key Information:

Vendor

Uutils

Status
Vendor
CVE Published:
22 April 2026

What is CVE-2026-35341?

A flaw in uutils coreutils mkfifo permits unauthorized modification of file permissions on existing files. If mkfifo encounters an existing file at the intended path, it fails to abort the operation, leading to a subsequent set_permissions execution that alters the permissions of the existing file to default modes (typically 644 after umask). This inadvertent change can expose sensitive files, including SSH private keys, to unauthorized access by other users on the system.

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zellic
.