CVE-2026-82474: Sudo-Project Sudo

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve, bypassing policy enforcement and logging.

Affected products

Published 2026-08-29. Last modified 2026-09-10.