HIGHVulnerability

CVE-2026-82474

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve, bypassing policy enforcement and logging.

Properties

severity
HIGH
score
7.8
epss_score
0.00131
cve_id
CVE-2026-82474
vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
published_at
2026-08-29T17:17:59.910
last_modified
2026-09-02T18:21:27.450
epss_percentile
0.03015

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Protection Mechanism Failure

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82474 — Ninja Signal Threat Intelligence | Ninja Signal