CVE-2026-8933
snap-confine Local Privilege Escalation via Capabilities Misconfiguration or Flaw in Execution Environment Setup
Description
A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installsen·The Hacker News· Research Linux Kernel privilege-escalation
- Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installsen·The Hacker News· Patch Ubuntu privilege-escalation
- CVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confineen-us·Qualys Security Blog· Patch Ubuntu privilege-escalation
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-8933 and every CVE in our database. Create a free account — no credit card required.
Create Free Account