CVE-2026-8933
CVSS 7.8 HIGH: a local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally…
Vulnerabilities & Exploits
Canonical’s confinement change did not just miss a corner case. On default Ubuntu Desktop installs, a low-privilege user can turn a sandbox setup race into full root, so the broken assumption is that snap confinement always contains local damage.
Qualys says CVE-2026-8933 affects Ubuntu Desktop 24.04, 25.10, and 26.04 through snap-confine. The flaw came from a security-hardening change that introduced the race, and Canonical patches plus Qualys detections are now available.
For fleet owners, the important point is that this is host takeover, not a narrow app escape. Once local root is possible, endpoint controls and persistence on the machine are at risk even if the original user account stays low privilege.
3 sources · Jul 22
CVSS 7.8 HIGH: a local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally…
The Hacker News
Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
CVE-2026-8933 combines two snap-confine races that could turn local Ubuntu access into root on default Desktop 24.04, 25.10, and 26.04 installs.
originalInfosecurity Magazine
Ubuntu snap-confine Vulnerability Enables Local Root Access
New Ubuntu snap-confine race condition lets local users escalate to root on default installs
originalQualys
CVE-2026-8933: Local Privilege Escalation in Ubuntu snap-confine | Qualys
Qualys TRU discovered CVE-2026-8933, a High-severity Local Privilege Escalation in snap-confine affecting Ubuntu Desktop 24.04, 25.10, and 26.04.
originalPart of the PlainSec briefing for 2026-07-22
Every edition of this story: Ubuntu Hardening Change Opens Default Desktop to Root