https://seclists.org/oss-sec/2026/q3/192: LPE in snapd and other vulnerabilities
Published Jul 21, 2026
·Updated
Affected Software
4 affected components
Canonical snapd (snap-confine)=set-capabilities versions of snap-confine
Canonical snapd (snap-confine) on Ubuntu Desktop 26.04=default set-capabilities /usr/lib/snapd/snap-confine
Canonical snapd (snap-confine) on Ubuntu Desktop 25.10=default set-capabilities /usr/lib/snapd/snap-confine
Canonical snapd (snap-confine) on Ubuntu Desktop 24.04=default set-capabilities /snap/snapd/current/usr/lib/snapd/snap-confine
Frequently Asked Questions
1
What is the severity of CVE-2026-8933?
CVE-2026-8933 is classified as a local privilege escalation vulnerability that could allow an attacker to gain elevated permissions.
2
How do I fix CVE-2026-8933?
To fix CVE-2026-8933, update your snapd package to the latest version provided by Canonical.
3
Which versions of snapd are affected by CVE-2026-8933?
CVE-2026-8933 affects set-capabilities versions of snap-confine in Ubuntu Desktop 24.04, 25.10, and 26.04.
4
What is the impact of exploiting CVE-2026-8933?
Exploiting CVE-2026-8933 allows an attacker to execute arbitrary commands with elevated privileges on the affected system.
5
Is there a workaround for CVE-2026-8933 until a patch is available?
It is recommended to restrict access to the snapd service as a temporary workaround until a patch is applied.