Fixes are available for 3 vulnerabilities reported in snapd, each with assigned CVE IDs and CVSS scores.
- CVE-2026-8933, discovered by Qualys, allows local attackers to escalate privileges. It impacts default installations of Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. The CVSS 3.1 score assigned to the vulnerability is 7.8 (high).
- CVE-2026-15226, discovered by Zygmunt Krynicki, Canonical team member, allows local attackers to escape snap confinement from confined root to unconfined root. The CVSS 3.1 score assigned to the vulnerability is 8.4 (high).
- CVE-2024-5300 discovered by James Henstridge, Canonical team member, allows a sandboxed application to access hashed user passwords. This vulnerability impacts installations of Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS Ubuntu, 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 26.04 LTS where systemd-userdbd is available. The CVSS 3.1 score assigned to the vulnerability is 5.6 (medium).
Affected releases
The following table lists the affected snaps. Revisions with patches will be updated as they are released.
| Snap name |
Channel |
Remediation status |
| snapd |
latest/stable |
pending (2.76.1) publication |
| snapd |
fips-updates/stable |
not planned |
| core |
latest/stable |
pending |
The snapd package distributed via the Ubuntu archive is also affected in the following releases. Fixes have been released as security updates.
| Release |
Package Name |
Fixed Version |
| Xenial (16.04) |
snapd |
2.61.4ubuntu0.16.04.1+esm4 |
| Bionic (18.04) |
snapd |
2.61.4ubuntu0.18.04.1+esm4 |
| Focal (20.04) |
snapd |
2.67.1+20.04ubuntu1~esm3 |
| Jammy (22.04) |
snapd |
2.76+ubuntu22.04.1 |
| Noble (24.04) |
snapd |
2.76+ubuntu24.04.1 |
| Resolute (26.04) |
snapd |
2.76+ubuntu26.04.3 |