CVE-2026-8933
CVSS 7.8 HIGH: a local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally…
Vulnerabilities · 54 days ago
Canonical’s confinement change did not just miss a corner case. On default Ubuntu Desktop installs, a low-privilege user can turn a sandbox setup race into full root, so the broken assumption is that snap confinement always contains local damage.
Qualys says CVE-2026-8933 affects Ubuntu Desktop 24.04, 25.10, and 26.04 through snap-confine. The flaw came from a security-hardening change that introduced the race, and Canonical patches plus Qualys detections are now available.
For fleet owners, the important point is that this is host takeover, not a narrow app escape. Once local root is possible, endpoint controls and persistence on the machine are at risk even if the original user account stays low privilege.
CVSS 7.8 HIGH: a local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally…
3 sources covering this story
Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
CVE-2026-8933 combines two snap-confine races that could turn local Ubuntu access into root on default Desktop 24.04, 25.10, and 26.04 installs.
Ubuntu snap-confine Vulnerability Enables Local Root Access
New Ubuntu snap-confine race condition lets local users escalate to root on default installs
CVE-2026-8933: Local Privilege Escalation in Ubuntu snap-confine | Qualys
Qualys TRU discovered CVE-2026-8933, a High-severity Local Privilege Escalation in snap-confine affecting Ubuntu Desktop 24.04, 25.10, and 26.04.
Part of the PlainSec briefing for 2026-07-23