
🚨High - sudoers NOTBEFORE/NOTAFTER TZ Time Window Bypass (CVE-2026-96512) In sudo, sudoers rules using NOTBEFORE/NOTAFTER with timestamps missing the trailing 'Z' are evaluated using the caller-controlled TZ environment variable. A local user can shift time checks by ~25 hours so expired/invalid windows are treated as valid, enabling command execution outside the intended window (no auth bypass). Rules with 'Z' are not affected. 👉Affected: sudo (sudoers NOTBEFORE/NOTAFTER timestamps without trailing 'Z')
