CVE-2026-82474
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve, bypassing policy enforcement and logging.
- Published Aug 29, 2026
- CVSS 8.5 high
- 0.1% chance of exploitation in the next 30 days (EPSS)
- A fix is available