A high-severity flaw in Ubuntu’s open-source snap-confine component lets local users gain root privileges on default desktop installations. Canonical has released patches after Qualys disclosed the vulnerability and urged immediate updates.
A high-severity vulnerability in the open-source snap-confine component of Ubuntu allows any local user to gain full root privileges on default installations of Ubuntu Desktop 24.04, 25.10 and 26.04. Tracked as CVE-2026-8933, the flaw was discovered by the Qualys Threat Research Unit (TRU) and disclosed on July 21, 2026. It marks the second snap-confine privilege-escalation vulnerability reported by Qualys in the past four months.
The vulnerability stems from a security hardening change introduced by Canonical in July 2025, when snap-confine shifted from a setuid-root model to a set-capabilities model. Researchers uncovered two race conditions that let attackers mount a malicious FUSE filesystem before namespace isolation and exploit a symlink race to overwrite arbitrary files.
The exploit can then bypass AppArmor by placing a malicious .rules file in /run/udev/rules.d/ and triggering systemd-udevd to execute arbitrary commands as root.
Jason Soroko, Senior Fellow, Certificate Lifecycle Management (CLM) Provider, Sectigo, said least privilege “is not a property of a binary alone. It depends on the full sequence of operations around that binary.”
Because the affected snapd package ships with default Ubuntu Desktop installations, employee workstations, developer systems and administrative endpoints are at risk. Ubuntu 24.04 systems are affected only if updated to vulnerable snapd versions, making version verification essential.
Canonical has released patches through the Ubuntu Security Team, while Qualys has published a detailed advisory and proof-of-concept, urging administrators to update snapd immediately.











































































