CVE Tools
Back to feed
Patch released Ubuntu privilege-escalation

Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs

The Hacker News·By The Hacker News··3 min read
CVE Tools coverage

Researchers have revealed a critical local privilege escalation (LPE) vulnerability in the snap-confine component of Ubuntu, allowing unprivileged users to escalate their privileges to root on default desktop installations. Tracked as CVE-2026-8933 (CVSS score: 7.8), this flaw affects Ubuntu Desktop versions 24.04, 25.10, and 26.04. The vulnerability arises from a race condition during sandbox initialization, enabling attackers to manipulate file permissions and inject malicious rules into system directories. This could lead to full system compromise. To mitigate the risk, users are advised to update their systems with the latest patches for snapd.