PT-2026-60898 · Sh · Sh
CVE-2026-54552
·
Published
2026-07-17
·
Updated
2026-08-18
CVSS v3.1
7.9
High
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
sh versions prior to 2.2.4
Description
A privilege management flaw exists on Linux/Unix-like systems where the
uid option performs an incomplete privilege drop. When a privileged parent process spawns a child process using uid to reduce privileges, the child process changes its UID and primary GID but fails to reset its supplementary groups. Consequently, the child process may retain privileged supplementary groups from the parent, such as docker, disk, shadow, or sudo. This allows a subprocess intended to run with limited permissions to access sensitive resources or files granted to those groups, potentially leading to privilege escalation.Recommendations
Upgrade to version 2.2.4 or later.
Avoid using the
uid option when the target user is less privileged.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sh