CVE-2025-32462HIGH 8.8EPSS p86.7%

CVE-2025-32462CVE-2025-32462

Description

Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines.

Scoring

CVSS 3.18.8 (HIGH)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS3.24% probability of exploitation · percentile 86.7% · 2026-06-18T12:00:27Z
Published2025-06-30
Last modified2025-11-03

Underlying weaknesses· 1

CWE-863

References

  1. https://access.redhat.com/security/cve/cve-2025-32462
  2. https://bugs.gentoo.org/show_bug.cgi?id=CVE-2025-32462
  3. https://explore.alas.aws.amazon.com/CVE-2025-32462.html
  4. https://lists.debian.org/debian-security-announce/2025/msg00118.html
  5. https://security-tracker.debian.org/tracker/CVE-2025-32462
  6. https://ubuntu.com/security/notices/USN-7604-1
  7. https://www.openwall.com/lists/oss-security/2025/06/30/2
  8. https://www.secpod.com/blog/sudo-lpe-vulnerabilities-resolved-what-you-need-to-know-about-cve-2025-32462-and-cve-2025-32463/

1

TypeTargetConfidenceTier
WeaknessIncorrect Authorizationcwe-8630%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability
CVE
CVE-2026-35535
CVE
CVE-2025-25269
CVE
Sudo Heap-Based Buffer Overflow Vulnerability
CVE
CVE-2025-32980
CVE
CVE-2025-45311
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.