CVE-2026-96512 is a local authorization-bypass vulnerability in Sudo versions 1.8.20 through 1.9.17p2. Sudo evaluates sudoers NOTBEFORE and NOTAFTER restrictions using local-time parsing when timestamps omit an explicit trailing Z timezone indicator. Its time parsing can use the invoking user's inherited TZ environment variable. An authenticated local user with an affected, time-restricted sudoers rule can set an extreme POSIX timezone offset to shift the interpreted authorization window by approximately 25 hours. This can make expired rules appear valid or future-dated rules become active early. Sudo password authentication and PAM checks still apply.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This six-file repository is an operational local privilege-escalation reproduction for SudoTimeWarp, CVE-2026-96512. It targets sudo Date_Spec authorization rules whose NOTBEFORE or NOTAFTER value omits both a trailing Z and an explicit offset. On affected sudo versions, parsing uses mktime(), which re-reads the invoking unprivileged user's TZ environment variable. A POSIX inline timezone such as TZ=XXX24 shifts interpretation of the zone-less authorization timestamp, potentially making a recently expired sudo rule valid again. The exploit does not bypass PAM authentication and does not grant privileges to a user with no existing sudoers authorization; it revives an existing dated grant. poc.sh is the standalone root-run lab harness. It backs up and rewrites /etc/sudoers, creates a poc user, pins system time zone presentation to UTC, and executes five controls: an in-window rule, expired rules with no TZ and TZ=UTC, the exploit using TZ=XXX24, and an expired timestamp with Z. It reports affected only if the expired zone-less rule becomes root execution with XXX24 while the UTC-suffixed form remains denied. repro-admin.sh is the privileged setup half, supporting expired, valid, expired-z, and escalation policy scenarios. repro-attacker.sh deliberately refuses root execution and demonstrates the unprivileged attack using only its process environment and sudo. Its escalation scenario differentiates a permanent /usr/bin/id grant from an expired broad ALL grant, then uses /bin/sh to demonstrate arbitrary root command execution. Dockerfile supplies a disposable Debian trixie lab, installs the distribution sudo and tzdata packages, copies the scripts to /poc, and starts poc.sh. No exploit code performs network communication; documented external CVE and source-commit URLs occur only in README reference material. The primary security-sensitive local resources are the setuid sudo binary, /etc/sudoers, TZ environment state, and, for the demonstration, /etc/repro-proof.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity local privilege-escalation vulnerability in Sudo's processing of time-based sudoers restrictions. A local authenticated user with an existing Sudo rule containing NOTBEFORE or NOTAFTER conditions can supply a crafted TZ environment variable to alter timestamp interpretation and bypass the intended authorization window. It does not bypass Sudo password authentication or PAM.
A high-severity local privilege-escalation vulnerability in Sudo's parsing of time-based sudoers authorization rules. A user who already has a Sudo rule governed by NOTBEFORE or NOTAFTER conditions can use a crafted TZ value to shift time interpretation by roughly 25 hours and bypass the intended schedule.
A local authorization-bypass flaw in sudo's evaluation of NOTBEFORE and NOTAFTER sudoers time restrictions. An unprivileged authenticated user can manipulate the inherited TZ environment variable when a timestamp lacks a trailing Z indicator, shifting the effective authorization window by up to about 25 hours and allowing commands outside the intended time window. It does not bypass sudo authentication.
A vulnerability identified as CVE-2026-96512 affecting Sudo packages on CentOS 7/8 and Red Hat Enterprise Linux 7/8/9/10. The provided CVSS v3 vector describes a local, low-complexity attack requiring low privileges, with high confidentiality, integrity, and availability impact.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.