๐Ÿ” CVE Alert

CVE-2026-8933

HIGH 7.8

snap-confine Local Privilege Escalation via Capabilities Misconfiguration or Flaw in Execution Environment Setup

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority.

CWE CWE-250
Published Jul 21, 2026
Stay Ahead of the Next One

Get instant alerts for

Be the first to know when new high vulnerabilities are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Canonical / Ubuntu 26.04 LTS
All versions affected
Canonical / Ubuntu 24.04 LTS
All versions affected
Canonical / Ubuntu 22.04 LTS
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
ubuntu.com: https://ubuntu.com/security/CVE-2026-8933

Credits

Qualys Security Advisory Team