Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-8933

42
FAUCET Score

A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority.

First published: Jul 21, 2026Last modified: Jul 21, 2026

Impacted Technologies

VendorProductVersion(s)CPE
Https://Github.Com/CanonicalSnapd
>= 2.75.0, < 2.76.1CNA affecteddefault unaffected
CanonicalUbuntu 22.04 LTS
Range not provided by sourceCNA affecteddefault affected
CanonicalUbuntu 24.04 LTS
Range not provided by sourceCNA affecteddefault affected
CanonicalUbuntu 26.04 LTS
Range not provided by sourceCNA affecteddefault affected

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
7.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0018 is in the 30th percentile among its peer group of 16,994 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

ubuntupatch availablevia ubuntu_usn
Product: snapd (bionic)Fixed in: 2.61.4ubuntu0.18.04.1+esm4
ubuntupatch availablevia ubuntu_usn
Product: snapd (focal)Fixed in: 2.67.1+20.04ubuntu1~esm3
ubuntupatch availablevia ubuntu_usn
Product: snapd (jammy)Fixed in: 2.76+ubuntu22.04.1
ubuntupatch availablevia ubuntu_usn
Product: snapd (noble)Fixed in: 2.76+ubuntu24.04.1
ubuntupatch availablevia ubuntu_usn
Product: snapd (resolute)Fixed in: 2.76+ubuntu26.04.3
ubuntupatch availablevia ubuntu_usn
Product: snapd (xenial)Fixed in: 2.61.4ubuntu0.16.04.1+esm4

Vendor Advisories (1)

ubuntuUSN-8579-1

snapd vulnerabilities

Jul 21, 2026

References

ubuntu.com / security/CVE-2026-8933