CVE Tools

CVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confine

Qualys Security BlogBy Saeed Abbasi3 min read

PatchUbuntusnapd

Our summary

A critical local privilege escalation (LPE) vulnerability, CVE-2026-8933, has been discovered in the snap-confine component used by recent versions of Ubuntu Desktop. This flaw could allow unprivileged users to escalate privileges to root due to a race condition during sandbox initialization. The affected systems include Ubuntu Desktop 24.04, 25.10, and 26.04. Exploitation involves leveraging two concurrent race conditions to manipulate file ownership and bypass AppArmor confinement. Canonical has issued patches through its security team, and organizations are urged to update their snapd packages immediately.

Read at Qualys Security Blog

Below is the opening; the full story is at Qualys Security Blog.

From Qualys Security Blog

The Qualys Threat Research Unit (TRU) has identified a Local Privilege Escalation (LPE) vulnerability in snap-confine (CVE-2026-8933). This flaw allows an unprivileged local user to gain full root access on default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The issue stems from a security hardening change that inadvertently introduced a race condition during sandbox initialization.…

Continue at Qualys Security Blog

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store