CVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confine
CYBERSECURITY FEATURED ANALYSIS

CVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confine

BY

Saeed Abbasi

SOURCE

Qualys Security Blog

DATE

READ

1 min read

The Qualys Threat Research Unit (TRU) has identified a Local Privilege Escalation (LPE) vulnerability in snap-confine (CVE-2026-8933). This flaw allows an unprivileged local user to gain full root access on default …

The Qualys Threat Research Unit (TRU) has identified a Local Privilege Escalation (LPE) vulnerability in snap-confine (CVE-2026-8933). This flaw allows an unprivileged local user to gain full root access on default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The issue stems from a security hardening change that inadvertently introduced a race condition during sandbox