Sudo

Vendor:

First CVE: May 16, 2002 · Active for 24 years

26
Total CVEs
More Total CVEs than 95% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
7.7%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Sudo over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 16, 2002
24 years ago
Most Recent CVE
Apr 3, 2026
112 days ago

CVE Severity & Scoring

Sudo26 CVEs
All CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local18 (69.2%)
Network7 (26.9%)
Unknown1 (3.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (76.9%)
High5 (19.2%)
Unknown1 (3.8%)
User Interaction
None25 (96.2%)
Unknown1 (3.8%)
Required0 (0.0%)
Privileges Required
Low18 (69.2%)
High3 (11.5%)
None4 (15.4%)
Unknown1 (3.8%)

Top CVEs

Signals from CVEs in this product scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg
Jan 26, 20217.899YESYES
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
Jun 30, 20257.896YESYES
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invok
Oct 17, 20198.884NOYES
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a lo
Jan 18, 20237.875NOYES
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in
Jan 29, 20207.848NOYES
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines.
Jun 30, 20258.845NOYES
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and c
Jun 5, 20176.437NOYES
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiple wildcards in /etc/sudoers, as demonstr
Nov 17, 20157.235NOYES
Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p (
May 16, 20027.833NOYES
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to p
Apr 3, 20267.831NONO

Exploit Exposure

Signals from CVEs in this product scope (26 CVEs).

CISA KEV
2 CVEs
7.7% of CVEs· 97th percentile
Metasploit
3 CVEs
11.5% of CVEs· 97th percentile
Nuclei
3 CVEs
11.5% of CVEs· 97th percentile
ExploitDB
9 CVEs
34.6% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (26 CVEs).

Media Mentions

Signals from CVEs in this product scope (26 CVEs).

Top CNAs Publishing CVEs For Sudo

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.9.517.899.3%11
1.9.1738.010.4%12
1.9.1317.21.7%00
1.9.1227.637.0%01
1.8.917.00.5%00
1.8.817.00.5%00
1.8.2018.20.6%00
1.8.1517.00.5%00
1.8.1417.00.5%00
1.8.1317.00.5%00
1.8.1217.00.5%00
1.8.1117.00.5%00
1.8.1017.00.5%00