CVE-2026-8933
James Henstridge discovered that snapd's default apparmor template did not restrict access to systemd-userdbd varlink interface. A local attacker could possibly use this issue to obtain sensitive information. (CVE-2024-5300) Qualys discovered that snap-confine can be tricked to create attacker-controlled files at certain privileged locations. A local attacker could possibly use this issue to bypass intended restrictions and escalate privileges to root. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-8933) Zygmunt Krynicki discovered that snapd's default seccomp template did not restrict the creation of executables with the set-user-ID attribute. A local attacker could possibly use this issue to create and execute setuid binaries. (CVE-2026-15226)
CSIRTS triage
- What
- Multiple vulnerabilities could allow local attackers to obtain sensitive information or escalate privileges.
- Who is affected
- Users of snapd on Ubuntu 22.04 LTS, 24.04 LTS, and 26.04 LTS.
- Urgency
- Remediation is important due to the potential for information disclosure and privilege escalation.
- Action
- Update snapd to the latest version to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-8933
Get an email if CVE-2026-8933 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
Advisory coverage (3)
- high[NEW] [high] snapd: Multiple Vulnerabilitiescert-bund · 2026-07-22
- highCVE-2026-8933: A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core comp…nvd · 2026-07-21
- unknownUSN-8579-1: snapd vulnerabilitiesubuntu · 2026-07-21
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-8933)