Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment.
The high-severity flaw, tracked as CVE-2026–8933 (CVSS score: 7.8), impacts default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The disclosure comes as 442 security flaws in Linux have been publicized over the past three days.
“The issue stems from a security hardening change that inadvertently introduced a race condition during sandbox initialization,” Saeed Abbasi, head of Threat Research Unit (TRU) and director of product at Qualys, said.
