logo

Ubuntu snap-confine Vulnerability Enables Local Root Access

ID: 78dda23e-b2ce-576c-b0f9-d73f7ac66a99

STIX ID: report--78dda23e-b2ce-576c-b0f9-d73f7ac66a99

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

...
...

A high-severity local privilege escalation (CVE-2026-8933) in snap-confine affects default Ubuntu Desktop installations (24.04, 25.10, 26.04); Qualys TRU found race conditions during sandbox setup (temporary directory ownership window, FUSE mount and symlink races) enabling a local user to escalate to root, provided technical analysis and PoC, and Canonical has released snapd patches—administrators should verify versions and apply updates immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.