securityaffairs.com 7/22/2026, 11:05:44 PM · external

Ubuntu Snap race condition CVE-2026-8933 enables root takeover

Ubuntu Snap race condition CVE-2026-8933 enables root takeover
CyberSIXT Evidence Panel
Primary Source blog.qualys.com
CISA KEV Not in KEV
Patch Patch Status Unknown

THE article discusses CVE-2026-8933, a high-severity security vulnerability in Ubuntu affecting versions 24.04, 25.10, and 26.04. Disclosed by Qualys, this local privilege escalation flaw allows unauthorized users to gain root access through a race condition in the `snap-confine` component of Ubuntu's Snap system. The vulnerability occurs during temporary file creation in the `/tmp` directory, which can be exploited to create malicious symbolic links, ultimately compromising system integrity. Users are advised to update their snapd packages to mitigate risk.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline