CVE-2026-8933

EUVD-2026-46262
A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations).
Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 11.84%
Debian logo
Debian Releases
Debian Product
Codename
snapd
bookworm
2.57.6-1+deb12u1
fixed
bookworm (security)
2.57.6-1+deb12u1
fixed
bullseye
not-affected
forky
2.76.3-2
fixed
sid
2.76.3-2
fixed
trixie
ignored
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
snapd
bionic
not-affected
focal
not-affected
jammy
Fixed 2.76+ubuntu22.04.1
released
noble
Fixed 2.76+ubuntu24.04.1
released
resolute
Fixed 2.76+ubuntu26.04.3
released
xenial
not-affected