CVE-2025-32462: Sudo Project Sudo

High severity, CVSS 8.8. EPSS: 4.5% chance of exploitation in the next 30 days.

Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines.

Affected products

  • Sudo Project Sudo: before 1.9.17 (fixed in 1.9.17); version 1.9.17 only

Published 2025-06-30. Last modified 2026-07-14.