Sudo Time-Based Access Control Flaw in Sudo Software by Sudo Project
CVE-2026-96512

7.8HIGH

What is CVE-2026-96512?

A vulnerability exists within the Sudo software affecting time-based access controls when configured with NOTBEFORE or NOTAFTER rules that lack a trailing 'Z' timezone identifier. This flaw results in improper evaluation of timestamps, relying on the TZ environment variable set by the invoking user. Consequently, an unprivileged user can manipulate the TZ variable to extend the validity of expired permissions by adjusting the time window by as much as 25 hours. While overall authentication processes remain intact, this misconfiguration poses a significant risk, allowing unauthorized command execution outside scheduled time frames.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Upstream acknowledges Ermenson Junior (Independent security research) as the original reporter.
.