Multiple security vulnerabilities have been identified in Ubuntu's Snap package and application management system. These vulnerabilities allow local attackers to gain root privileges through various exploitation techniques, including race conditions and timing issues. The affected versions include Ubuntu Desktop 24.04, 25.10, and 26.04.
CVE-2026-8933 (CVSS 7.8 — High): A high-severity local privilege escalation vulnerability affects default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. An unprivileged local attacker can exploit the issue to gain root access by leveraging a race condition in snap-confine's sandbox initialization process.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in Ubuntu's Snap package and application management system. These vulnerabilities allow local attackers to gain root privileges through various exploitation techniques, including race conditions and timing issues. The affected versions include Ubuntu Desktop 24.04, 25.10, and 26.04.
CVE-2026-8933 (CVSS 7.8 — High): A high-severity local privilege escalation vulnerability affects default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. An unprivileged local attacker can exploit the issue to gain root access by leveraging a race condition in snap-confine's sandbox initialization process.[emaillocker id="1283"]
CVE-2026-3888 (CVSS 7.8 — High): A high-severity local privilege escalation vulnerability affects default installations of Ubuntu Desktop version 24.04 and later. An unprivileged local attacker can exploit the issue to escalate privileges to full root access through the interaction of two standard system components: snap-confine and systemd-tmpfiles.
These vulnerabilities collectively present a significant risk to affected systems, particularly those with default installations of Ubuntu Desktop.
We recommend you to update Ubuntu Desktop to version 24.04.
The following reports contain further technical details:
[/emaillocker]