Sandbox Confinement Bypass in Canonical Snapd
CVE-2026-15226

8.4HIGH

Key Information:

Vendor
CVE Published:
21 July 2026

What is CVE-2026-15226?

A vulnerability exists in Canonical's snapd, allowing applications within a confined snap environment to bypass sandbox protections. The issue arises from the default seccomp security templates, which fail to appropriately filter dangerous system calls. This oversight enables malicious processes to create or manipulate binaries with set-user-ID attributes, which could lead to unauthorized privilege escalation and access within the container namespace. Canonical has addressed this issue by enhancing the seccomp template to prevent the creation and execution of potentially harmful setuid executables within sandboxed environments.

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zygmunt Krynicki
.