The record
Written from the 2 reports below. Nothing here is unsourced.
- Security researchers have disclosed a high-severity local privilege escalation vulnerability, CVE-2026-8933, in snap-confine, a component used by Canonical's snapd to build sandboxed environments for snap applications.
- The flaw affects default installations of Ubuntu Desktop 24.04, 25.10, and 26.04, and lets an unprivileged user with existing access gain root control via race conditions during sandbox setup, including symlink and malicious FUSE mount tricks.
- It stems from a hardening change that inadvertently introduced a race window, and a fix is already available in snapd updates.
- Administrators are advised to update promptly and verify installed snapd versions rather than rely on release age.
What to watch next
- Deployment of the latest snapd updates across Ubuntu Desktop systems, especially 24.04, 25.10, and 26.04
- Verification of installed snapd versions, since even updated 24.04 systems can carry the affected variant
- Further disclosures among the 442 Linux security flaws publicized in recent days
What changed2
Every report on this story, newest first. Times are when each outlet published.
Coverage2
2 reports
English national1Wire / agency1
Filed from India ×1, United States ×1
Named United States · United Kingdom · Canonical · snap-confine · snapd · Ubuntu · Jason Soroko · Qualys · Saeed Abbasi · Sectigo
- The Hacker NewsUbuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs[1]English national· neutral

- NVD / CVECVE-2026-8933: A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure [2]Wire / agency
The 2 reports are listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.