Fixes are available for 3 vulnerabilities reported in snapd, each with assigned CVE IDs and CVSS scores.

  • CVE-2026-8933, discovered by Qualys, allows local attackers to escalate privileges. It impacts default installations of Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. The CVSS 3.1 score assigned to the vulnerability is 7.8 (high).
  • CVE-2026-15226, discovered by Zygmunt Krynicki, Canonical team member, allows local attackers to escape snap confinement from confined root to unconfined root. The CVSS 3.1 score assigned to the vulnerability is 8.4 (high).
  • CVE-2024-5300 discovered by James Henstridge, Canonical team member, allows a sandboxed application to access hashed user passwords. This vulnerability impacts installations of Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS Ubuntu, 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 26.04 LTS where systemd-userdbd is available. The CVSS 3.1 score assigned to the vulnerability is 5.6 (medium).

Affected releases

The following table lists the affected snaps. Revisions with patches will be updated as they are released.

Snap name Channel Remediation status
snapd latest/stable pending (2.76.1) publication
snapd fips-updates/stable not planned
core latest/stable pending

The snapd package distributed via the Ubuntu archive is also affected in the following releases. Fixes have been released as security updates.

Release Package Name Fixed Version
Xenial (16.04) snapd 2.61.4ubuntu0.16.04.1+esm4
Bionic (18.04) snapd 2.61.4ubuntu0.18.04.1+esm4
Focal (20.04) snapd 2.67.1+20.04ubuntu1~esm3
Jammy (22.04) snapd 2.76+ubuntu22.04.1
Noble (24.04) snapd 2.76+ubuntu24.04.1
Resolute (26.04) snapd 2.76+ubuntu26.04.3