PT-2026-61944 · Canonical · Snapd

·

CVE-2026-15226

·

Published

2026-07-21

·

Updated

2026-07-21

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Canonical snapd (affected versions not specified)
Description A sandbox confinement bypass exists in the internal execution environment compiler (snap-confine). The default seccomp security templates, which are used to restrict system calls, fail to filter or reject operations that create or manipulate file execution flags with set-user-ID attributes. This allows an application in a strictly confined environment to compile or drop binaries and apply setuid properties to them. A malicious process can then execute these binaries to bypass sandboxing assumptions, remove restriction policies, or perform privileged actions within the container namespace.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15226
USN-8579-1

Affected Products

Snapd