EIP-2026-103760

PRE-CVE

(Tod Miller's) Sudo/SudoEdit 1.6.9p21/1.7.2p4 - Local Privilege Escalation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-103760. PoCs published by kingcope.

AI-analyzed exploit summary This exploit leverages a vulnerability in older versions of Sudo (1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4) to gain root privileges by manipulating the sudoedit functionality. It creates a malicious script in /tmp and executes it via sudo, bypassing intended restrictions.

Description

(Tod Miller's) Sudo/SudoEdit 1.6.9p21/1.7.2p4 - Local Privilege Escalation

Exploits (1)

exploitdb WORKING POC VERIFIED
by kingcope · bashlocalmultiple
https://www.exploit-db.com/exploits/11651

This exploit leverages a vulnerability in older versions of Sudo (1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4) to gain root privileges by manipulating the sudoedit functionality. It creates a malicious script in /tmp and executes it via sudo, bypassing intended restrictions.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4
Auth required
Prerequisites: Local access to the system · Permission to edit a file via sudoedit
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026