Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sudo Project

First CVE: May 16, 2002Active for: 24 yearsTotal CVEs: 26
83.2
VTI Score
TOP TARGET

Sudo is a foundational privilege-delegation utility deployed on virtually every Unix and Linux system, making the sudo project among the most critical single-product vendors in the security landscape despite its narrow portfolio. Vulnerabilities affecting sudo frequently acquire public exploit code and have a moderate tendency toward confirmed in-the-wild exploitation, reflecting both the utility's ubiquity and the high value of privilege-escalation flaws to attackers. The recurring exposure centers on weakness classes characteristic of a setuid binary sitting at the boundary between user and kernel privilege: race conditions in shared resource handling, improper input validation and output escaping, link-following issues, and privilege-management logic errors that can permit unprivileged users to gain elevated access. Defenders should treat sudo advisories as high-priority across all Unix and Linux infrastructure; remediation typically requires coordinated patching of every affected system. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
2.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
7.7%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Sudo Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 16, 2002
24 years ago
Most Recent CVE
Apr 3, 2026
112 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-3156HIGH
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg
Jan 26, 20217.899YESYES
CVE-2025-32463HIGH
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
Jun 30, 20257.896YESYES
CVE-2019-14287HIGH
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invok
Oct 17, 20198.884NOYES
CVE-2023-22809HIGH
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a lo
Jan 18, 20237.875NOYES
CVE-2019-18634HIGH
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in
Jan 29, 20207.848NOYES
CVE-2025-32462HIGH
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines.
Jun 30, 20258.845NOYES
CVE-2017-1000367MEDIUM
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and c
Jun 5, 20176.437NOYES
CVE-2015-5602HIGH
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiple wildcards in /etc/sudoers, as demonstr
Nov 17, 20157.235NOYES
CVE-2002-0184HIGH
Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p (
May 16, 20027.833NOYES
CVE-2026-35535HIGH
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to p
Apr 3, 20267.831NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
12%
81%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local18 (69.2%)
Network7 (26.9%)
Unknown1 (3.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (76.9%)
High5 (19.2%)
Unknown1 (3.8%)
User Interaction
None25 (96.2%)
Unknown1 (3.8%)
Required0 (0.0%)
Privileges Required
Low18 (69.2%)
High3 (11.5%)
None4 (15.4%)
Unknown1 (3.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
2 CVEs
7.7% of CVEs· 100th percentile
Metasploit
3 CVEs
11.5% of CVEs· 98th percentile
Nuclei
3 CVEs
11.5% of CVEs· 97th percentile
ExploitDB
9 CVEs
34.6% of CVEs· 80th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sudo Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sudo Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sudo Project's Products

View all 2 CNAs →

Top CWEs