Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sudo

First CVE: May 16, 2002Active for: 24 yearsTotal CVEs: 26

Sudo is a foundational privilege-escalation utility deployed across Unix and Linux systems that allows authorized users to execute commands with elevated privileges, making it a critical component of system administration and access control across the landscape. The vendor's limited disclosure history centers on the sudo command itself and reflects the parsing and privilege-validation demands inherent to the utility's core function. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 56% of tracked vendors
2.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
7.7%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sudo over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 16, 2002
24 years ago
Most Recent CVE
Apr 3, 2026
112 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-3156HIGH
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg
Jan 26, 20217.899YESYES
CVE-2025-32463HIGH
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
Jun 30, 20257.896YESYES
CVE-2019-14287HIGH
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invok
Oct 17, 20198.884NOYES
CVE-2023-22809HIGH
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a lo
Jan 18, 20237.875NOYES
CVE-2019-18634HIGH
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in
Jan 29, 20207.848NOYES
CVE-2025-32462HIGH
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines.
Jun 30, 20258.845NOYES
CVE-2017-1000367MEDIUM
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and c
Jun 5, 20176.437NOYES
CVE-2015-5602HIGH
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiple wildcards in /etc/sudoers, as demonstr
Nov 17, 20157.235NOYES
CVE-2002-0184HIGH
Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p (
May 16, 20027.833NOYES
CVE-2026-35535HIGH
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to p
Apr 3, 20267.831NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
12%
81%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local18 (69.2%)
Network7 (26.9%)
Unknown1 (3.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (76.9%)
High5 (19.2%)
Unknown1 (3.8%)
User Interaction
None25 (96.2%)
Unknown1 (3.8%)
Required0 (0.0%)
Privileges Required
Low18 (69.2%)
High3 (11.5%)
None4 (15.4%)
Unknown1 (3.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
2 CVEs
7.7% of CVEs· Bottom 1%
Metasploit
3 CVEs
11.5% of CVEs· Bottom 1%
Nuclei
3 CVEs
11.5% of CVEs· Bottom 1%
ExploitDB
9 CVEs
34.6% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sudo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sudo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sudo's Products

View all 2 CNAs →