CVE-2026-93658
uutils coreutils 0.0.18 before 0.10.0 Privilege Escalation via setuid
CVSS Score
7.0
EPSS Score
0.0%
EPSS Percentile
0th
uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes fail. Attackers can execute leftover setuid files with elevated privileges when ownership change operations fail on capability-restricted systems.
| CWE | CWE-281 |
| Vendor | uutils |
| Product | coreutils |
| Published | Sep 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for uutils coreutils
Be the first to know when new high vulnerabilities affecting uutils coreutils are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
uutils / coreutils
0.0.18 < 0.10.0
References
github.com: https://github.com/uutils/coreutils/security/advisories/GHSA-cgg3-923w-v53m github.com: https://github.com/uutils/coreutils/pull/13629 github.com: https://github.com/uutils/coreutils/commit/7c87ab04fee8e52d989fb2625568a3eeda1b1f55 github.com: https://github.com/uutils/coreutils/blob/0.9.0/src/uu/install/src/install.rs github.com: https://github.com/uutils/coreutils vulncheck.com: https://www.vulncheck.com/advisories/uutils-coreutils-0.0.18-before-0.10.0-privilege-escalation-via-setuid
Credits
Ali Firas (thesmartshadow)