Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
PatchUbuntuOur summary
Researchers have revealed a critical local privilege escalation (LPE) vulnerability in the snap-confine component of Ubuntu, allowing unprivileged users to escalate their privileges to root on default desktop installations. Tracked as CVE-2026-8933 (CVSS score: 7.8), this flaw affects Ubuntu Desktop versions 24.04, 25.10, and 26.04. The vulnerability arises from a race condition during sandbox initialization, enabling attackers to manipulate file permissions and inject malicious rules into system directories. This could lead to full system compromise. To mitigate the risk, users are advised to update their systems with the latest patches for snapd.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.