CVE-2026-8933
Publication date 21 July 2026
Last updated 22 July 2026
Ubuntu priority
Cvss 3 Severity Score
Description
A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority.
Why is this CVE high priority?
Local Privilege Escalation
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| snapd | 26.04 LTS resolute |
Fixed 2.76+ubuntu26.04.3
|
| 24.04 LTS noble |
Fixed 2.76+ubuntu24.04.1
|
|
| 22.04 LTS jammy |
Fixed 2.76+ubuntu22.04.1
|
|
| 20.04 LTS focal |
Not affected
|
|
| 18.04 LTS bionic |
Not affected
|
|
| 16.04 LTS xenial |
Not affected
|
Severity score breakdown
CVSS version: CVSS v3.0
Base score
7.8 · High
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References
Related Ubuntu Security Notices (USN)
- USN-8579-1
- snapd vulnerabilities
- 21 July 2026