CVE- 2026-8933 is a privilege escalation flaw in the snap-confine component of Ubuntu Desktop systems (versions 26.04, 25.10, and 24.04) that allows any local user to gain root access. Discovered by Qualys, the vulnerability stems from a change in how snap-confine was shipped, affecting systems using set-capabilities instead of setuid-root. While an exploit exists, no real-world attacks have been reported. The issue was fixed by Canonical on July 21, 2026. Users are advised to update snapd immediately and limit local shell access until patched.
snap-confine Flaw CVE-2026-8933 Lets Any User Get Root on Ubuntu
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Ubuntu snap confine flaw lets local users gain root access
cybersixt.com
-
Ubuntu snap-confine Vulnerability Enables Local Root Access
cybersixt.com
-
snap-confine Flaw CVE-2026-8933 Lets Any User Get Root on Ubuntu
securityonline.info