Canonical disclosed and patched three snapd vulnerabilities, led by CVE-2026-8933, a high-severity local privilege escalation flaw in snap-confine that can let a local user gain root on affected Ubuntu Desktop systems. Qualys reported that Ubuntu Desktop 26.04, 25.10, and fully updated 24.04 installations using the file-capabilities configuration for snap-confine are exposed because the process retains near-root capabilities while operating with the attacker’s effective UID, allowing attacker-owned files and directories to be created during a race window. The flaw can be exploited through symlink-based arbitrary file creation and permission changes, then by planting a malicious udev rule in an AppArmor-permitted path under /run/udev/, which can be triggered to execute attacker-controlled commands as root via systemd-udevd.
Canonical also addressed CVE-2026-15226, a snap-confine sandbox confinement bypass caused by missing setuid restrictions in seccomp templates, which could let code running inside a strictly confined snap create or manipulate setuid binaries and weaken confinement boundaries. A third issue, CVE-2024-5300, involved an AppArmor base profile misconfiguration that could expose hashed passwords through systemd-userdbd. Fixes are scheduled in snapd 2.76.1 and corresponding Ubuntu package updates for Xenial, Bionic, Focal, Jammy, Noble, and Resolute, with Canonical publishing advisory USN-8579-1; Qualys said it had a working exploit for CVE-2026-8933 but reported no evidence of active exploitation.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Canonical resolved CVE-2026-15226, a snap-confine sandbox confinement bypass caused by missing setuid restrictions in seccomp templates. Fixed Ubuntu package versions were published for multiple supported releases, with affected versions listed as earlier than 2.76.1.
Canonical disclosed CVE-2026-8933, CVE-2024-5300, and CVE-2026-15226 in snapd, describing impacts, affected Ubuntu releases, and package updates. Canonical said fixes were being issued and that advisory USN-8579-1 would be published.
The coordinated public release for CVE-2026-8933 took place, making details of the snap-confine local privilege escalation issue public. Reporting states Canonical released coordinated fixes the same day.
Qualys reported CVE-2026-8933, a local privilege escalation flaw in snap-confine, to the Ubuntu Security Team. The bug affects Ubuntu Desktop systems where snap-confine uses Linux capabilities instead of setuid-root.
Ubuntu published a security notice page for CVE-2026-3888, introducing a distinct vulnerability not covered by the existing timeline entries. The reference identifies Ubuntu as the source and anchors the publication on 2026-03-17.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
17 references tracked. Mallory keeps watching after this page renders.
linuxsecurity.com
Open sourcecybersecuritynews.com
Open sourcecsirt.sk
Open sourcescworld.com
Open sourceblog.qualys.com
Open sourceseclists.org
Open sourceblog.qualys.com
Open sourceubuntu.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.