Sudo Time-Based Access Control Flaw in Sudo Software by Sudo Project
CVE-2026-96512
7.8HIGH
What is CVE-2026-96512?
A vulnerability exists within the Sudo software affecting time-based access controls when configured with NOTBEFORE or NOTAFTER rules that lack a trailing 'Z' timezone identifier. This flaw results in improper evaluation of timestamps, relying on the TZ environment variable set by the invoking user. Consequently, an unprivileged user can manipulate the TZ variable to extend the validity of expired permissions by adjusting the time window by as much as 25 hours. While overall authentication processes remain intact, this misconfiguration poses a significant risk, allowing unauthorized command execution outside scheduled time frames.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Upstream acknowledges Ermenson Junior (Independent security research) as the original reporter.