Sudo Vulnerability in Execveat System Call Bypasses Policy Enforcement
CVE-2026-82474
8.5HIGH
What is CVE-2026-82474?
The Sudo application, up to version 1.9.17p2, is susceptible to a vulnerability where the intercept policy checks are not enforced for the execveat system call when operating in ptrace-based intercept mode. As a result, users who have permission to execute certain commands may exploit this weakness to call denied programs directly or via fexecve, circumventing the intended policy enforcement and logging mechanisms. This flaw undermines the security model of Sudo by potentially allowing unauthorized command execution.
Affected Version(s)
sudo 0 <= 1.9.17p2
References
CVSS V4
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
XlabAI Team of Tencent Xuanwu Lab
Guannan Wang
Zhanpeng Liu
Guancheng Li
Nofil Qasim
Quentin Chalabi
