CVE-2026-82474

Summary

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve, bypassing policy enforcement and logging.

Affected Software

VendorProductVersion RangeStatus
sudo-projectsudo0 <= 1.9.17p2affected

Weaknesses

  • CWE-693: Protection Mechanism Failure

References