CVE-2026-8933
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
2.75.0 < 2.76.1 | affected | ||
| Canonical | Ubuntu 26.04 LTS | 2.76+ubuntu26.04.3 | unaffected |
| Canonical | Ubuntu 24.04 LTS | 2.76+ubuntu24.04.1 | unaffected |
| Canonical | Ubuntu 22.04 LTS | 2.76+ubuntu22.04.1 | unaffected |
Weaknesses
- CWE-250: CWE-250 Execution with unnecessary privileges
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.