Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-82474

Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-693 Fallo del mecanismo de protección
Fecha de publicación:
29/08/2026
Última modificación:
29/08/2026

Descripción

*** Pendiente de traducción *** Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve, bypassing policy enforcement and logging.