CVE-2026-93658

Source
https://cve.org/CVERecord?id=CVE-2026-93658
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93658.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93658
Aliases
  • GHSA-cgg3-923w-v53m
Downstream
Published
2026-09-18T14:23:20Z
Modified
2026-09-19T03:47:31Z
Severity
  • 7.3 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
uutils coreutils 0.0.18 before 0.10.0 Privilege Escalation via setuid
Details

uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes fail. Attackers can execute leftover setuid files with elevated privileges when ownership change operations fail on capability-restricted systems.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-281"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93658.json"
}
References

Affected packages

Git / github.com/uutils/coreutils

Affected ranges

Type
GIT
Repo
https://github.com/uutils/coreutils
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.0.18"
        },
        {
            "fixed": "0.10.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.0.18
0.0.19
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.30
0.0.30-delete
0.1.0
0.2.0
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Other
latest-commit

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93658.json"