Threat reportVulnerabilityTL-2026-1633
CVE-2026-8933: Race Condition in Ubuntu snap-confine Enables Local Privilege Escalation to Root
CVE-2026-8933 (TL-2026-1633) is a high-severity software vulnerability scored CVSS 7.8, first published 2026-07-22 and last reviewed 2026-07-25. It has no confirmed attribution, affects Canonical snapd / snap-confine (Ubuntu Desktop), references 1 CVE (CVE-2026-8933), maps to 17 MITRE ATT&CK techniques (T1036, T1059.004, T1068), and is covered by 9 detection rules and 29 indicators of compromise.
- CVSS
- 7.8/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 17MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 29Indicators of compromise
Key facts for TL-2026-1633
- Threat ID
- TL-2026-1633
- Severity
- HIGH
- CVSS
- 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- all sectors running ubuntu desktop, government administration, finance, health, technology, education, critical-infrastructure
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 29
- Updates
- 2026-07-25 · 2 updates · revalidated 2× · latest source
Malware and tooling in CVE-2026-8933
Malware and tooling: FUSE (Filesystem in Userspace)
How CVE-2026-8933 works
A dual race-condition (TOCTOU) vulnerability in Ubuntu's snap-confine sandbox launcher, introduced when Canonical hardened snap-confine from a set-uid-root binary to a set-capabilities model in July 2025, lets an unprivileged local user mount a malicious FUSE filesystem over a temporary scratch directory, inject symlinks, and drop a malicious udev rule to gain full root code execution. Discovered by Qualys TRU; publicly disclosed and patched July 21, 2026 with no reported in-the-wild exploitation.
CVE-2026-8933 is a High-severity (CVSS 3.1: 7.8, AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) local privilege escalation vulnerability in snap-confine, the setuid/capabilities-based sandbox launcher that snapd uses to construct the confined execution environment for snap applications on Ubuntu. In July 2025, Canonical moved snap-confine away from a traditional set-uid-root binary model to a 'set-capabilities' model (retaining a narrow set of Linux capabilities such as CAP_SYS_ADMIN instead of full root) as a defense-in-depth hardening measure. That change inadvertently introduced a race-condition window during sandbox initialization.
When snap-confine prepares a snap's execution environment it creates a scratch directory under /tmp (e.g. /tmp/snap.rootfs_XXXXXX) that is briefly owned by the invoking unprivileged user before ownership is transferred to root via fchown(fd, 0, 0). Qualys TRU identified two concurrent, chainable race conditions in this window. First, an attacker mounts a malicious FUSE filesystem over the scratch directory immediately after its creation; because mount-namespace isolation is applied by snap-confine only later in the sequence, the FUSE mount remains externally accessible and can intercept/unmount snap-confine's subsequent operations. Second, when snap-confine opens files in that directory with open(full_path, O_CREAT|O_TRUNC, 0644) without the O_NOFOLLOW flag, an attacker-planted symlink causes the open() call to follow the link and write to an arbitrary attacker-chosen target instead of the intended sandbox file. A further permission-widening race (chmod 0666) can occur before the fchown() ownership transfer completes, extending the writable window.
To turn this arbitrary-write primitive into root code execution, the exploit targets /run/udev/**, a path that AppArmor's snap-confine security profile permits read-write access to. By redirecting the symlink race to write a malicious .rules file into /run/udev/rules.d/ and then triggering a FUSE mount/unmount cycle, the attacker causes systemd-udevd (which runs as root and processes udev events, including RUN+= directives in rule files) to execute an attacker-controlled command with full root privileges — completing the local privilege-escalation chain from unprivileged user to root with no user interaction and low attack complexity.
The flaw affects default installations of Ubuntu Desktop 22.04 LTS, 24.04 LTS, 25.10, and 26.04 running vulnerable snapd releases (approximately snapd 2.75.0 through 2.76.0) that use the set-capabilities snap-confine variant; systems still running the legacy set-uid-root snap-confine configuration are not affected. Qualys TRU (led by Saeed Abbasi) privately disclosed the issue to the Ubuntu Security Team on 2026-04-22; Canonical distributed fixes to the linux-distros coordination list on 2026-07-13 and published a public advisory on 2026-07-14, with full coordinated disclosure and patch release on 2026-07-21 via Ubuntu Security Notice USN-8579-1, which also bundled fixes for two related snapd flaws: CVE-2024-5300 (AppArmor template flaw exposing hashed user passwords via the systemd-userdbd varlink interface, affecting Ubuntu releases back to 16.04 LTS) and CVE-2026-15226 (seccomp template flaw permitting setuid binary creation, enabling escape from confined root to unconfined root). No in-the-wild exploitation or public PoC release has been reported for CVE-2026-8933 as of disclosure; Qualys withheld full working exploit code pending patch adoption. Given that snap is a default packaging format across most modern Ubuntu Desktop and Ubuntu Core installations, and that the vulnerability requires only unprivileged local code execution as a precondition (readily obtainable via a malicious downloaded binary, compromised low-privilege service account, or post-initial-access foothold), this issue warrants priority patching and detection coverage for privilege-escalation chains involving snap-confine, FUSE mounts, and udev rule file writes.
MITRE ATT&CK techniques used in TL-2026-1633
Defense Evasion
T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1211 Exploitation for Stealth; T1564.001 Hide Artifacts: Hidden Files and Directories
Execution
T1059.004 Command and Scripting Interpreter: Unix Shell; T1569 System Services
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1078.003 Valid Accounts: Local Accounts; T1548 Abuse Elevation Control Mechanism; T1548.001 Abuse Elevation Control Mechanism: Setuid and Setgid; T1611 Escape to Host
Discovery
T1082 System Information Discovery; T1518.001 Software Discovery: Security Software Discovery
defense-impairment
T1222.002 Linux and Mac Permissions
Persistence
T1546.017 Event Triggered Execution: Udev Rules
Credential Access
Resource Development
Affected products and versions in CVE-2026-8933
- Canonical — snapd / snap-confine (Ubuntu Desktop)
Vulnerable versions: Ubuntu Desktop 22.04 LTS (snapd < 2.76+ubuntu22.04.1); Ubuntu Desktop 24.04 LTS (snapd < 2.76+ubuntu24.04.1); Ubuntu Desktop 25.10 (snapd, set-capabilities snap-confine variant); Ubuntu Desktop 26.04 (snapd < 2.76+ubuntu26.04.3); snapd 2.75.0 through 2.76.0 (upstream semver range)
Fixed in: snapd 2.76+ubuntu26.04.3; snapd 2.76+ubuntu24.04.1; snapd 2.76+ubuntu22.04.1; snapd 2.67.1+20.04ubuntu1~esm3 (ESM); snapd 2.61.4ubuntu0.18.04.1+esm4 (ESM); snapd 2.61.4ubuntu0.16.04.1+esm4 (ESM)
Remediation for CVE-2026-8933
Patches
- snapd 2.76+ubuntu26.04.3 (Ubuntu 26.04 LTS)
- snapd 2.76+ubuntu24.04.1 (Ubuntu 24.04 LTS)
- snapd 2.76+ubuntu22.04.1 (Ubuntu 22.04 LTS)
- snapd 2.67.1+20.04ubuntu1~esm3 (Ubuntu 20.04 LTS, Ubuntu Pro/ESM required)
- snapd 2.61.4ubuntu0.18.04.1+esm4 (Ubuntu 18.04 LTS, Ubuntu Pro/ESM required)
- snapd 2.61.4ubuntu0.16.04.1+esm4 (Ubuntu 16.04 LTS, Ubuntu Pro/ESM required)
Immediate actions
- Update snapd to the patched version for your Ubuntu release via apt update && apt install --only-upgrade snapd
- Verify installed snapd version explicitly — do not assume patched status from release/update date alone, per Qualys and vendor guidance
- On systems that cannot patch immediately, restrict local unprivileged account creation/logon and monitor for unexpected FUSE mounts under /tmp
Workarounds
- No fully effective workaround without patching; where patching is delayed, restrict unprivileged local access and monitor /run/udev/rules.d and /tmp/snap.rootfs_* for anomalous writes
Longer-term hardening
- Deploy auditd/eBPF-based monitoring for udev rule file writes outside of package-manager-driven changes (auditctl -w /run/udev/rules.d -p wa)
- Deploy EDR/behavioral detection for mount() syscalls targeting snap-confine scratch directories (/tmp/snap.rootfs_*)
- Track Canonical/Ubuntu security notices for snapd and apply patches promptly given snapd's default-installed, high-privilege attack surface
CVEs associated with CVE-2026-8933
Weaknesses (CWE) in CVE-2026-8933
Timeline of CVE-2026-8933
- Historical related snap-confine flaw 'Oh Snap! More Lemmings' (CVE-2021-44731) disclosed, establishing a recurring pattern of race-condition issues in snap-confine's privileged temp-file handling.
- CVE-2022-3328 discloses a related snap-confine race condition, combinable with CVE-2021-44731 for privilege escalation — an additional historical precedent in the recurring snap-confine sandbox-initialization bug pattern.
- Canonical shifts snap-confine from a set-uid-root binary to a set-capabilities model as a security hardening measure, inadvertently introducing the race-condition window later identified as CVE-2026-8933.
- Related snap-confine/systemd-tmpfiles race condition CVE-2026-3888 (CVSS 7.8) disclosed by Qualys, involving a similar cleanup-window privilege escalation; public PoC later published on GitHub.
- Qualys Threat Research Unit privately discloses the snap-confine race-condition vulnerability to the Ubuntu Security Team.
- Canonical distributes patches to the coordinated linux-distros disclosure mailing list ahead of public release.
- Initial public advisory information for the snapd fixes becomes available.
- Ubuntu publishes the official CVE-2026-8933 tracking page confirming Jammy/Noble/Resolute as fixed and Focal/Bionic/Xenial as not affected.
- Qualys Threat Research Unit (Saeed Abbasi) publishes full technical writeup and advisory for CVE-2026-8933, detailing the FUSE/symlink/udev exploit chain.
- Canonical publishes a companion Ubuntu Discourse post ('Snapd - multiple vulnerabilities fixed') summarizing the three bundled CVEs, listing per-release package versions, and instructing users that a system reboot is required after updating snapd.
- Canonical publishes Ubuntu Security Notice USN-8579-1, releasing fixed snapd packages for Ubuntu 16.04 through 26.04 LTS and formally assigning CVE-2026-8933 alongside CVE-2024-5300 and CVE-2026-15226.
- As of this date, CVE-2026-8933 has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog and no confirmed in-the-wild exploitation has been reported; risk is driven by public PoC availability and broad default-install impact.
- The Hacker News, Infosecurity Magazine, Phoronix, and other outlets publish coverage summarizing the vulnerability and urging patch adoption.
- Runtime-security vendor Exein publishes a detection write-up (Exein Photon) mapping the vulnerable open()-without-O_NOFOLLOW pattern to a blockable eBPF rule.
Update history for TL-2026-1633
- 2026-07-25 — CVE-2026-8933: Local Privilege Escalation in Ubuntu snap-confine via Race Condition: What changed No escalation-eligible field changes. The newer report characterizes exploitability as THEORETICAL (no public PoC tool) and status as PATCHED, versus the existing record's POC_PUBLIC/ACTIVE — since this would be a downgrade, it
- 2026-07-22 — CVE-2026-8933: Local Privilege Escalation via Race Condition in Ubuntu snap-confine: What changed No severity, exploitability, or status escalation — both reports independently assess HIGH/7.8/POC_PUBLIC/ACTIVE. The newer report adds a fourth root-cause weakness (CWE-362, generic race condition) alongside the existing CWE-3
Sources cited for CVE-2026-8933
- Ubuntu snap-confine flaw could give attackers root access
- CVE-2026-8933: Local Privilege Escalation in Ubuntu snap-confine
- Qualys Security Advisory: snap-confine set-capabilities race condition
- USN-8579-1: snapd vulnerabilities
- NVD - CVE-2026-8933
- Ubuntu snap-confine Vulnerability Enables Local Root Access
- Three New Ubuntu Snap Vulnerabilities Made Public - One Dates Back To Ubuntu 16.04 LTS
- Snapd - multiple vulnerabilities fixed
- How to Patch Ubuntu Snap Vulnerabilities (2026)
- Ubuntu snap-confine flaw can give attackers root access
Detection coverage for TL-2026-1633
As of 2026-07-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1633 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.