CVE-2026-8933

Published Jul 21, 2026

Last updated a month ago

Overview

Description
A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority.
Source
security@ubuntu.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

security@ubuntu.com
CWE-250

Social media

Hype score
Not currently trending
  1. 🐧 𝗔𝗟𝗘𝗥𝗧𝗔 𝗟𝗜𝗡𝗨𝗫: 2 fallas críticas de escalamiento de privilegios 🔹 CVE-2026-8933 → Ubuntu Desktop 🔹 CVE-2026-64600 "RefluXFS" → RHEL, CentOS, Rocky, AlmaLinux, Fedora, Amazon Linux Más info 👇👇 https://t.co/9PL0Ewg3GT #Ciberse

    @LeonelM41262107

    24 Jul 2026

    131 Impressions

    2 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2026-8933: a snap-confine flaw gives any local user root on default Ubuntu Desktop 24.04, 25.10 and 26.04. Ironically introduced by a 2025 least-privilege hardening change. Patch shipped Jul 21. https://t.co/4ElHRDxS2Y #cybersecurity #Linux

    @JNitterauer

    23 Jul 2026

    98 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. A critical flaw in Ubuntu's snap-confine component, CVE-2026-8933, allows local users to gain root access on default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. This vulnerability stems from a race condition introduced during a security hardening change in July 2025.

    @dailytechonx

    23 Jul 2026

    113 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🔒💥 ¡ALERTA DE SEGURIDAD EN UBUNTU! Canonical revela 3 vulnerabilidades críticas en snapd que afectan versiones desde Ubuntu 16.04 LTS. CVE-2026-8933 permite escalado de privilegios. CVE-2026-15226 posibilita escape de confinación. CVE-2024-5300 expone contraseñas

    @DiarioBitcoin

    23 Jul 2026

    932 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  5. 🚨 High-Severity Ubuntu Alert Qualys TRU has disclosed CVE-2026-8933, a local privilege escalation in snap-confine that grants full root access to any unprivileged local user on default Ubuntu Desktop installations. The flaw arises from race conditions in temporary directory h

    @FriendOfTheInst

    22 Jul 2026

    112 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.