Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.4

CVE-2026-82474: Sudo lets users run blocked programs on Linux

CVE-2026-82474 · published 5 days ago
Summary

On Linux systems, the sudo tool up to version 1.9.17p2 can be tricked to run programs that administrators have said should be blocked. This means a user who is supposed to run only certain approved commands could start any other program without the usual warning or record, potentially creating a security risk. The fix is to upgrade sudo to a newer version and review who has sudo rights.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
Ecosystem VendorProductAffected versions
Debian:14 debian sudo All versions
– sudo-project sudo <= 1.9.17p2
Debian:11 debian sudo All versions
Debian:12 debian sudo All versions
Debian:13 debian sudo All versions
Original advisory text
Sudo through 1.9.17p2 Intercept Policy Bypass via execveat
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve, bypassing policy enforcement and logging.
Severity
8.4 High
CVSS 3.1: 7.8 (NVD)
CVSS 4.0: 8.5 (NVD)
CVSS 3.1: 7.8 (OSV)
CVSS 4.0: 8.4 (OSV)
Exploitation
EPSS <1%
Type
CWE-693Protection Mechanism Failure
Timeline
Published29 Aug 2026
Updated3 Sep 2026
First seen29 Aug 2026
Sources
CVE-2026-82474 · MITRE
Monitor software like this
Free during beta