7.8
CVE-2026-8933
- EPSS 0.22%
- Veröffentlicht 21.07.2026 14:02:19
- Zuletzt bearbeitet 22.07.2026 19:17:14
- CVE-Watchlists
- Unerledigt
snap-confine Local Privilege Escalation via Capabilities Misconfiguration or Flaw in Execution Environment Setup
A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Collection URLhttps://github.com/canonical
≫
Paket
snapd
Default Statusunaffected
Version
2.75.0
Version <
2.76.1
Status
affected
HerstellerCanonical
≫
Produkt
Ubuntu 26.04 LTS
Default Statusaffected
Version
2.76+ubuntu26.04.3
Status
unaffected
HerstellerCanonical
≫
Produkt
Ubuntu 24.04 LTS
Default Statusaffected
Version
2.76+ubuntu24.04.1
Status
unaffected
HerstellerCanonical
≫
Produkt
Ubuntu 22.04 LTS
Default Statusaffected
Version
2.76+ubuntu22.04.1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.121 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Canonical | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-250 Execution with Unnecessary Privileges
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://ubuntu.com/security/CVE-2026-8933