snap-confine local privilege escalation to root
snap-confine flaw on Ubuntu lets an unprivileged local user gain root on default Desktop 24.04, 25.10, and 26.04 installs. CVSS 7.8 high.
- Vendor
- Canonical
- Product
- snap-confine (Ubuntu Desktop 24.04 LTS, 25.10, 26.04)
- CVSS
- 7.8
- EPSS (exploit probability)
- N/A
- Status
- unpatched
- Published
A local privilege escalation vulnerability in snap-confine, the setuid-root binary that sets up AppArmor confinement for snap packages on Ubuntu, allows an unprivileged local user to obtain root access. The flaw affects default installations of Ubuntu Desktop 24.04 LTS, 25.10, and 26.04.
Mechanism: snap-confine runs with elevated privileges by design — configuring filesystem namespaces and AppArmor profiles requires root. A flaw in how it handles its execution path allows an unprivileged caller to subvert that elevated execution and obtain root on the host.
Exploitation: Local access required. No network exposure. The attacker must have an unprivileged shell account on the affected system.
Impact: Full local root. An attacker with any local account on a default Ubuntu Desktop installation can escalate to root via this vulnerability.
Affected versions: Ubuntu Desktop 24.04 LTS, 25.10, 26.04 — any default installation with snap present.
Patch: Monitor Ubuntu Security Notices for the CVE-2026-8933 advisory. Once published, update the snapd package via sudo apt update && sudo apt upgrade snapd. Ubuntu Server installations without snap installed are not affected.
Sources: NVD | The Hacker News
