- Description
- A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority.
- Source
- security@ubuntu.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- security@ubuntu.com
- CWE-250
- Hype score
- Not currently trending
🔒💥 ¡ALERTA DE SEGURIDAD EN UBUNTU! Canonical revela 3 vulnerabilidades críticas en snapd que afectan versiones desde Ubuntu 16.04 LTS. CVE-2026-8933 permite escalado de privilegios. CVE-2026-15226 posibilita escape de confinación. CVE-2024-5300 expone contraseñas
@DiarioBitcoin
23 Jul 2026
692 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
🚨 High-Severity Ubuntu Alert Qualys TRU has disclosed CVE-2026-8933, a local privilege escalation in snap-confine that grants full root access to any unprivileged local user on default Ubuntu Desktop installations. The flaw arises from race conditions in temporary directory h
@FriendOfTheInst
22 Jul 2026
99 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes