CVE-2026-82474 HIGH

CVE-2026-82474: Sudo through 1.9.17p2 Intercept Policy Bypass via execveat

Vendor Sudo-Project
Product sudo
Weakness CWE-693
Published August 29, 2026
Last update September 2, 2026

CVSS base score

8.5/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve, bypassing policy enforcement and logging.

Key dates

02Disclosure timeline

August 29, 2026 CVE published
September 2, 2026 Record updated

Related vulnerabilities

04Related CVE