A newly disclosed high-severity vulnerability in Sudo could allow local unprivileged Linux users to circumvent time-based restrictions set in sudoers policies This article explores severity vulnerability sudo. . Identified as CVE-2026-96512, the flaw arises from Sudo's handling of the attacker-controlled TZ environment variable when evaluating command authorization windows defined with the NOTBEFORE and NOTAFTER tags.
Red Hat has assigned Bug 2539327 to track the issue and has classified it as high severity and high priority. Sudo Flaw Allows Unprivileged Users to Evade Time-Based Restrictions Sudo's policies utilize NOTBEFORE and NOTAFTER to restrict when users can execute commands with elevated privileges. Administrators frequently employ these controls for temporary administrative access, maintenance periods, emergency access procedures, and automatically expiring privileged permissions.
According to the advisory, an attacker could use an extreme POSIX timezone setting, such as TZ=XXX24, to shift the effective authorization time by roughly 25 hours in either direction. For instance, an employee whose access to a sensitive maintenance command has expired could potentially manipulate timezone processing to make the entitlement appear valid again. Until patched packages are installed, defenders should scrutinize sudoers entries using NOTBEFORE or NOTAFTER directives, particularly for rules involving sensitive commands or those set to expire automatically.
Organizations should also combine temporary privilege assignments with centralized identity controls, short-lived credentials, comprehensive logging, and periodic reviews of sudoers policies. Explore for your team.











