


Perceptive Security
SOC/SIEM Consultancy

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific command…
Published:
29 August 2026 at 00:00:00
Alert date:
29 August 2026 at 20:03:20
Source:
nvd.nist.gov
Operating Systems, Identity & Access, Zero-Day Vulnerabilities
CVE-2026-82474 affects Sudo through version 1.9.17p2, where ptrace-based intercept mode fails to apply policy checks to the execveat system call. This allows users who are permitted to run specific commands to execute otherwise denied programs by calling execveat directly or via fexecve. The bypass circumvents both policy enforcement and logging mechanisms, representing a significant privilege escalation risk. The vulnerability exists in the exec_ptrace.c source file of the sudo-project. A patch has been committed to the official sudo repository to address this flaw. Organizations relying on Sudo's intercept mode for command restrictions are directly impacted. The issue highlights a gap in system call coverage within sudo's security enforcement layer.
Technical details
Mitigation steps:
Affected products:
Sudo 1.9.17p2 and earlier
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-82474
https://github.com/sudo-project/sudo
https://github.com/sudo-project/sudo/blob/v1.9.17p2/src/exec_ptrace.c
https://github.com/sudo-project/sudo/commit/71fbe42dcd5a1c8f799540583a2dfb2ae6221edf
https://www.vulncheck.com/advisories/sudo-through-1.9-17p2-intercept-policy-bypass-via-execveat
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
