CVE-2026-8933: snap-confine Local Privilege Escalation via Capabilities Misconfiguration or Flaw in Execution Environment Setup

Published Jul 21, 2026
·
Updated

A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority.

Affected Software

2 affected componentsFixes available
snap-confine
debian/snapd<=2.68.3-3+deb13u1, <=2.76-1
2.49-1+deb11u22.57.6-1+deb12u1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/snapd to a version that resolves this vulnerability.

    Fixed in 2.49-1+deb11u2Fixed in 2.57.6-1+deb12u1

Event History

Jul 21, 2026
CVE Published
via MITRE·02:02 PM
Data Sourced
via MITRE·02:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Jul 22, 2026
Data Sourced
via Launchpad·02:44 PM
Description
Jul 26, 2026
Data Sourced
via Debian·02:48 PM
DescriptionAffected Software
Aug 7, 2026
Data Sourced
via Ubuntu·02:58 PM
RemedyDescriptionSeverityAffected Software
May 8, 58583
Event
via FIRST·06:37 PM

Frequently Asked Questions

1

What is the severity of CVE-2026-8933?

The severity of CVE-2026-8933 is high with a score of 7.8.

2

How do I fix CVE-2026-8933?

To fix CVE-2026-8933, update to the latest patched version of snap-confine released by Canonical.

3

What type of vulnerability is CVE-2026-8933?

CVE-2026-8933 is a local privilege escalation vulnerability.

4

Which software is affected by CVE-2026-8933?

CVE-2026-8933 specifically affects Canonical snap-confine.

5

What is the impact of CVE-2026-8933?

The impact of CVE-2026-8933 can lead to unauthorized access and control over the system due to privilege escalation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203