CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-54552

highCVSS 7.9covered by 1 sourcefirst seen 2026-07-17
Impact The _uid option performed an incomplete privilege drop on Linux/Unix-like systems. When sh was run from a process with elevated privileges, such as root, and a command was launched with _uid=<unprivileged user>, the child process changed its UID and primary GID but did not reset its supplementary groups. As a result, the child process could retain the parent process’s supplementary groups, potentially including privileged groups such as root, docker, disk, shadow, or sudo. This could allow a subprocess that was expected to run with reduced privileges to access files or resources available to the original process’s supplementary groups. Users are impacted if they rely on _uid as a privilege boundary when launching commands from a privileged parent process. Patches Upgrade to version >= 2.2.4 Workarounds Avoid using _uid when the user represents a less-privileged user.

⚡ Watch CVE-2026-54552

Get an email if CVE-2026-54552 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-54552

CVE.org record

Embed the live status

CVE-2026-54552 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-54552 status](https://www.csirts.com/badge/CVE-2026-54552)](https://www.csirts.com/cve/CVE-2026-54552)