Impact
An AppArmor base profile misconfiguration in snapd allows strictly confined snap applications that run as root to interact with systemd-userdbd UNIX domain sockets. The service returns full user records, including hashed passwords from /etc/shadow, creating an information disclosure flaw identified as CWE-212 and CWE-1220.
Affected Systems
Canonical’s Ubuntu releases 16.04 LTS through 26.04 LTS are vulnerable when the systemd-userdbd service is installed and operational. The flaw is specific to systems that have snapd and the systemd-userdbd helper enabled; standard Ubuntu deployments do not include this service by default.
Risk and Exploitability
The CVSS base score of 5.6 indicates moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. This flaw encompasses both an information disclosure (CWE-212) and an access control bypass (CWE-1220). The attack vector is local; an attacker must run a confined snap with root privileges on a system where systemd-userdbd is active to retrieve all system password hashes.
OpenCVE Enrichment
Ubuntu USN