SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-8933

HIGH · CVSS 7.8 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

A local privilege escalation vulnerability in snap-confine, a core component of Canonical's snapd, allows unprivileged attackers to bypass security restrictions and execute arbitrary code with elevated root privileges. This issue specifically affects versions of snap-confine configured with set-capabilities, making it critical for organizations using snap applications to prioritize patching. System administrators and security teams should address this vulnerability promptly to mitigate the risk of unauthorized access and potential system compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-8933
Severity
HIGH
CVSS
7.8
EPSS
0.21%

Original NVD Description

A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority.