Back to overview

CVE-2026-8933

HIGH
7.8
CVSS 3.1
Description
A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority.

Metadata

CVE ID
CVE-2026-8933
State
PUBLISHED
Assigner
canonical
Reserved
2026-05-19 10:37 UTC
Published
2026-07-21 14:02 UTC
Last updated
2026-07-21 14:02 UTC
Primary CWE
CWE-250
CWE-250 Execution with unnecessary privileges
Sources
cve.org  ·  NVD

Severity & Metrics

7.8 HIGH CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products (4)
VendorProductPlatformVersions
2.75.0 < 2.76.1
Canonical Ubuntu 22.04 LTS Linux 2.76+ubuntu22.04.1
Canonical Ubuntu 24.04 LTS Linux 2.76+ubuntu24.04.1
Canonical Ubuntu 26.04 LTS Linux 2.76+ubuntu26.04.3
Weakness (CWE)
CWESourceDescription
CWE-250 cna CWE-250 Execution with unnecessary privileges
CVSS scores (1)
ScoreSeverityVersionSourceVector
7.8 HIGH 3.1 cna CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Back to overview