- Description
- A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority.
- Source
- security@ubuntu.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- security@ubuntu.com
- CWE-250
- Hype score
- Not currently trending
🐧 𝗔𝗟𝗘𝗥𝗧𝗔 𝗟𝗜𝗡𝗨𝗫: 2 fallas críticas de escalamiento de privilegios 🔹 CVE-2026-8933 → Ubuntu Desktop 🔹 CVE-2026-64600 "RefluXFS" → RHEL, CentOS, Rocky, AlmaLinux, Fedora, Amazon Linux Más info 👇👇 https://t.co/9PL0Ewg3GT #Ciberse
@LeonelM41262107
24 Jul 2026
131 Impressions
2 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-8933: a snap-confine flaw gives any local user root on default Ubuntu Desktop 24.04, 25.10 and 26.04. Ironically introduced by a 2025 least-privilege hardening change. Patch shipped Jul 21. https://t.co/4ElHRDxS2Y #cybersecurity #Linux
@JNitterauer
23 Jul 2026
98 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
A critical flaw in Ubuntu's snap-confine component, CVE-2026-8933, allows local users to gain root access on default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. This vulnerability stems from a race condition introduced during a security hardening change in July 2025.
@dailytechonx
23 Jul 2026
113 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
🔒💥 ¡ALERTA DE SEGURIDAD EN UBUNTU! Canonical revela 3 vulnerabilidades críticas en snapd que afectan versiones desde Ubuntu 16.04 LTS. CVE-2026-8933 permite escalado de privilegios. CVE-2026-15226 posibilita escape de confinación. CVE-2024-5300 expone contraseñas
@DiarioBitcoin
23 Jul 2026
932 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
🚨 High-Severity Ubuntu Alert Qualys TRU has disclosed CVE-2026-8933, a local privilege escalation in snap-confine that grants full root access to any unprivileged local user on default Ubuntu Desktop installations. The flaw arises from race conditions in temporary directory h
@FriendOfTheInst
22 Jul 2026
112 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes