A narrow sudoedit grant on Ubuntu 26.04 can be turned into arbitrary privileged file placement.
sudo-rs, the Rust sudo and su implementation shipped by Ubuntu 26.04 LTS.
Ubuntu describes a time-of-check/time-of-use race in sudo-rs sudoedit path handling: a local user granted the right to edit specific named files can win the race and have files placed in directories of their choosing instead. The point of a fine-grained sudoedit rule is that the list of files is the boundary, and this removes the boundary while leaving the rule looking intact.
Detail and 1 source
Ubuntu says the issue only affects systems configured with fine-grained sudoedit file editing permissions, which is not the default configuration.
The step nobody has written down is which target turns arbitrary privileged placement into reliable root execution on a stock 26.04 host — the notice does not say, and until someone does, this is a boundary failure rather than a demonstrated escalation.