THREAT OPS › Threat News › CVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confine
CVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confine
<p class="wp-block-paragraph">The <a href="https://www.qualys.com/tru" rel="noreferrer noopener" target="_blank">Qualys Threat Research Unit (TRU)</a> has identified a Local Privilege Escalation (LPE) vulnerability in snap-confine (CVE-2026-8933). This flaw allows an unprivileged local user to gain full root access on default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The issue stems
Indicators of compromise
- CVE-2026-8933cve
- https://www.qualys.com/truurl
- https://cdn2.qualys.com/advisory/2026/07/21/snap-confine-set-capabilities.txturl
- https://www.qualys.com/apps/cybersecurity-asset-managementurl
- https://www.qualys.com/apps/patch-managementurl
Original source: https://blog.qualys.com/category/vulnerabilities-threat-research