Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5005 articles · 188937 vulns · 37/41 feeds (7d)
← Back to list
7.8
CVE-2026-8933PATCHED
canonical · snap-confine

snap-confine Local Privilege Escalation via Capabilities Misconfiguration or Flaw in Execution Environment Setup

Description

A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority.

Affected Products

VendorProductVersions
canonicalsnap-confine2.75.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
canonicalubuntu 26.04 ltsmitre_affected90%
canonicalubuntu 24.04 ltsmitre_affected90%
canonicalubuntu 22.04 ltsmitre_affected90%
canonicallinuxcert_advisory90%
canonicalsnapcert_advisory90%

References

  • https://ubuntu.com/security/CVE-2026-8933(vdb-entry, issue-tracking)

Related News (9 articles)

Tier D
Heise Security20d ago
Rechteausweitungslücke in Ubuntu durch snap
→ No new info (linked only)
Tier D
The Hacker News21d ago
Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
→ No new info (linked only)
Tier B
BSI Advisories21d ago
[NEU] [hoch] snapd: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
Infosecurity Magazine21d ago
Ubuntu snap-confine Vulnerability Enables Local Root Access
→ No new info (linked only)
Tier E
Lobsters Security22d ago
Local Privilege Escalation in set-capabilities versions of snap-confine (CVE-2026-8933)
→ No new info (linked only)
Tier C
oss-security22d ago
Re: LPE in snapd and other vulnerabilities
→ No new info (linked only)
Tier C
VulDB22d ago
CVE-2026-8933 | Canonical Ubuntu 22.04/24.04/26.04 snap-confine sandbox
→ No new info (linked only)
Tier C
Qualys Blog22d ago
CVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confine
→ No new info (linked only)
Tier C
oss-security22d ago
LPE in snapd and other vulnerabilities
→ No new info (linked only)
CVSS 3.17.8 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
2.76.12.76+ubuntu26.04.32.76+ubuntu24.04.12.76+ubuntu22.04.1
CWECWE-250
PublishedJul 21, 2026
Last enriched21d agov3
Tags
race conditionFUSEsymlinkAppArmor bypasssystemd-udevdUbuntu Desktopprivilege escalationset-capabilities modelTOCTOU
Trending Score8
Source articles9
Independent8
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-45893EXP
apparmor: Fix & Optimize table creation from possibly unaligned memory
Trending: 9
HIGHCVE-2026-15226
snapd snap-confine Sandbox Confinement Bypass via Omission of setuid Restriction in Seccomp Templates
Trending: 4
CRITICALCVE-2026-11386
ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injection and Remote Code Execution
Trending: 3
MEDIUMCVE-2024-5300
AppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauthorized Access to Hashed Passwords via systemd-userdbd
Trending: 3
MEDIUMCVE-2026-9494
ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command Line
Trending: 2

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 21, 2026
Discovered by ZDM
Jul 21, 2026
Updated: vendor, product, affectedVersions, cweIds, tags
Jul 21, 2026
Updated: affectedVersions, tags
Jul 22, 2026
Patch Available
Jul 22, 2026

Version History

v3
Last enriched 21d ago
v3Tier D21d ago

Added detailed technical information about the race conditions, FUSE/symlink exploitation chain, AppArmor bypass mechanism via systemd-udevd, and expanded affected versions to include specific Ubuntu Desktop releases (24.04, 25.10, 26.04)

affectedVersionstags
via Infosecurity Magazine
v2Tier C22d ago

Added vendor (Canonical) and product (snapd), expanded affected versions to include specific Ubuntu Desktop releases, provided detailed technical exploitation mechanism involving FUSE race conditions and symlink attacks, confirmed exploit availability, added CWEs for race condition (CWE-362) and symlink following (CWE-59), and added relevant tags for race conditions and attack vectors.

vendorproductaffectedVersionscweIdstags
via Qualys Blog
v122d ago

Initial creation