[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3tUIKevYDuoFXdTHGn8q4DpatdhMhK9UEh1jcchAJVU":3},{"article":4,"iocs":36},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":30,"category":31,"article_tags":35},"71071219-d64b-47f8-9178-bb294dbdac71","New Ubuntu Desktop Vulnerability Turns Local Access Into Root Control","new-ubuntu-desktop-vulnerability-turns-local-access-into-root-control-abfdd9","A vulnerability in snap-confine lets an unprivileged user gain root access on affected Ubuntu Desktop systems. Install the latest snapd update to fix the issue.","Qualys researchers disclosed CVE-2026-8933, a high-severity vulnerability in Ubuntu's snap-confine component that allows unprivileged local users to escalate privileges to root. The flaw exploits a race condition in the Linux capabilities model where temporary files under \u002Ftmp briefly retain user ownership before transitioning to root, enabling attackers to mount malicious FUSE filesystems and redirect file operations to system locations. Ubuntu 22.04 LTS, 24.04 LTS, and 26.04 LTS are affected; users should install the latest snapd packages (2.76+ubuntu versions) and reboot.","CVE-2026-8933 in Ubuntu snap-confine allows unprivileged local users to gain root access.","SecurityNew Ubuntu Desktop Vulnerability Turns Local Access Into Root Control A vulnerability in snap-confine lets an unprivileged user gain root access on affected Ubuntu Desktop systems. Install the latest snapd update to fix the issue. byWaqasJuly 22, 20262 minute read Listen to this article 0:00 — ← 10s ▶ Play 10s → Speed 0.75× 1× 1.25× 1.5× 2× Voice Loading voices… Press play to start listening Qualys researchers have disclosed a high-severity vulnerability in Ubuntu’s snap-confine component that allows an unprivileged local user to gain root access. Tracked as CVE-2026-8933, the flaw can give an attacker complete administrative control of an affected computer. It is worth noting that the vulnerability does not provide remote access on its own. An attacker must already be able to run commands locally, whether through a compromised account, stolen credentials, another vulnerability, or a malicious application. Race Condition Abuses Sandbox Setup Snap-confine is part of snapd, the service that installs and manages snap packages. Its role is to prepare the restricted environment in which a snap application runs. The vulnerability appeared after a security hardening change replaced snap-confine’s setuid-root design with a Linux capabilities model. Under the newer setup, snap-confine runs using the calling user’s effective identity while retaining permissions needed to configure the sandbox. During that process, temporary files and directories are created under \u002Ftmp. They initially belong to the local user and are transferred to root ownership shortly afterward, leaving a brief window in which the user can still modify them. According to the Qualys technical analysis, exploitation of the vulnerability combines two race conditions. The attacker mounts a malicious FUSE filesystem over a temporary directory, then uses a symbolic link to redirect snap-confine’s file operation to a chosen system location. Before snap-confine transfers ownership, the attacker changes the target file’s permissions. This allows a malicious rules file to be written under \u002Frun\u002Fudev\u002Frules.d\u002F, where systemd-udevd can be triggered to execute commands as root. Successful exploitation gives the attacker the highest level of control available on Ubuntu. After which, they can alter files, create additional accounts, change security settings, and install other software. Ubuntu Updates Fix CVE-2026-8933 Qualys confirmed the vulnerable set-capabilities version on default installations of Ubuntu Desktop 24.04, 25.10 and 26.04. Ubuntu 24.04 systems are affected after receiving the relevant snapd packages. A security notice from Canonical, the company behind the Ubuntu project, lists Ubuntu 22.04 LTS, 24.04 LTS and 26.04 LTS as affected supported releases. Ubuntu 25.10 reached the end of its standard support period in July 2026, so users still running it should move to a supported release. Robert Coles, senior cybersecurity engineer at Black Duck, said the local access requirement does not remove the risk. An attacker who already has a limited foothold through stolen credentials, a malicious application or a separate vulnerability could use CVE-2026-8933 to take full control of the host. Coles advised organizations to identify affected Ubuntu devices, verify their snapd versions, and install the available fixes. Maintaining an accurate device inventory is particularly important when the same package is present on employee workstations and other Linux systems. Nevertheless, Ubuntu users should install all current system updates and reboot afterward. Canonical lists fixed snapd packages including 2.76+ubuntu26.04.3 for Ubuntu 26.04, 2.76+ubuntu24.04.1 for Ubuntu 24.04 and 2.76+ubuntu22.04.1 for Ubuntu 22.04. Waqas I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism. View Posts CanonicalCybersecurityLinuxQualysUbuntuUbuntu DesktopVulnerability Leave a Reply Cancel reply View Comments (0) Related Posts Read More Security Technology 5 Best Secure Container Images for Modern Applications (2026) Secure container images are now essential for modern apps. These five options help teams reduce risk, cut patching effort, and improve long-term security. byOwais Sultan Read More Hacking News Security Hacker Exploits Remote Code Execution Bug to Breach Facebook Security Andrew Leonov, a security researcher, discovered a critical remote execution bug on Facebook allowing him to breach the… byWaqas Read More Security Vulnerability in WhatsApp Allows Hackers To Read Your Conversation and View Media Bad news for WhatsApp users on Android. If you chat on WhatsApp, it’s time to be careful and avoid… byWaqas Read More Cyber Attacks Security Nissan Leaf Maybe At Threat Because of Vulnerable APIs Security researchers show how an attacker can access Nissan Leaf electric car by exploiting vulnerability in APIs By… byAli Raza","https:\u002F\u002Fhackread.com\u002Fubuntu-desktop-vulnerability-local-access-root-control\u002F","https:\u002F\u002Fhackread.com\u002Fwp-content\u002Fuploads\u002F2026\u002F07\u002Fubuntu-desktop-vulnerability-local-access-root-control.png","2026-07-22T11:15:37+00:00","2026-07-22T12:00:04.393618+00:00",9,[18,21,24,26,28],{"name":19,"type":20},"Canonical","vendor",{"name":22,"type":23},"Ubuntu Desktop","product",{"name":25,"type":23},"snapd",{"name":27,"type":23},"snap-confine",{"name":29,"type":20},"Qualys","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":30,"icon":32,"name":33,"slug":34},null,"Vulnerabilities","vulnerabilities",[],[37],{"type":38,"value":39,"context":40},"cve","CVE-2026-8933","High-severity privilege escalation vulnerability in Ubuntu snap-confine"]