snapd snap-confine Sandbox Confinement Bypass via Omission of setuid Restriction in Seccomp Templates

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2026-15226?

CVE-2026-15226 is a vulnerability classified as Execution with Unnecessary Privileges, affecting Ubuntu 26.04 LTS, Ubuntu 24.04 LTS, Ubuntu 22.04 LTS, and 3 more products. This vulnerability is rated High, with a CVSS score of 8.4. Current sources do not report this vulnerability as exploited.

Analyzing data...

Overview

Original source data

A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler (snap-confine). The default seccomp security templates generated by the engine to restrict system calls do not filter or reject process operations capable of creating or manipulating file execution flags with set-user-ID attributes. Consequently, an application running within a strictly confined snap environment can successfully compile or drop binaries and apply setuid properties to them. If a compromised or malicious process inside the snap sandbox executes these generated setuid binaries, it can potentially circumvent architectural sandboxing assumptions, drop intended restriction policies, or execute privileged actions inside the container namespace that should otherwise be strictly blocked. The vulnerability has been resolved by hardening the seccomp template engine to block the execution and creation of setuid executables by sandboxed snap processes.

Affected products and scope

The analysis could not be completed. The original vulnerability data remains available below.

Technical details

The analysis could not be completed. The original vulnerability data remains available below.

Exploitability

The analysis could not be completed. The original vulnerability data remains available below.

Technical impact

The analysis could not be completed. The original vulnerability data remains available below.

Business impact

The analysis could not be completed. The original vulnerability data remains available below.

Remediation

The analysis could not be completed. The original vulnerability data remains available below.

Detection

The analysis could not be completed. The original vulnerability data remains available below.
Sources (7)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan