Threat reportVulnerabilityTL-2026-1633

CVE-2026-8933: Race Condition in Ubuntu snap-confine Enables Local Privilege Escalation to Root

highACTIVE

CVE-2026-8933 (TL-2026-1633) is a high-severity software vulnerability scored CVSS 7.8, first published 2026-07-22 and last reviewed 2026-07-25. It has no confirmed attribution, affects Canonical snapd / snap-confine (Ubuntu Desktop), references 1 CVE (CVE-2026-8933), maps to 17 MITRE ATT&CK techniques (T1036, T1059.004, T1068), and is covered by 9 detection rules and 29 indicators of compromise.

CVSS
7.8/10High
CVEs
1Referenced vulnerabilities
Techniques
17MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
29Indicators of compromise

Key facts for TL-2026-1633

Threat ID
TL-2026-1633
Severity
HIGH
CVSS
7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
all sectors running ubuntu desktop, government administration, finance, health, technology, education, critical-infrastructure
Target regions
Global
Detection rules
9
Indicators of compromise
29
Updates
2026-07-25 · 2 updates · revalidated 2× · latest source

Malware and tooling in CVE-2026-8933

Malware and tooling: FUSE (Filesystem in Userspace)

How CVE-2026-8933 works

A dual race-condition (TOCTOU) vulnerability in Ubuntu's snap-confine sandbox launcher, introduced when Canonical hardened snap-confine from a set-uid-root binary to a set-capabilities model in July 2025, lets an unprivileged local user mount a malicious FUSE filesystem over a temporary scratch directory, inject symlinks, and drop a malicious udev rule to gain full root code execution. Discovered by Qualys TRU; publicly disclosed and patched July 21, 2026 with no reported in-the-wild exploitation.

CVE-2026-8933 is a High-severity (CVSS 3.1: 7.8, AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) local privilege escalation vulnerability in snap-confine, the setuid/capabilities-based sandbox launcher that snapd uses to construct the confined execution environment for snap applications on Ubuntu. In July 2025, Canonical moved snap-confine away from a traditional set-uid-root binary model to a 'set-capabilities' model (retaining a narrow set of Linux capabilities such as CAP_SYS_ADMIN instead of full root) as a defense-in-depth hardening measure. That change inadvertently introduced a race-condition window during sandbox initialization.

When snap-confine prepares a snap's execution environment it creates a scratch directory under /tmp (e.g. /tmp/snap.rootfs_XXXXXX) that is briefly owned by the invoking unprivileged user before ownership is transferred to root via fchown(fd, 0, 0). Qualys TRU identified two concurrent, chainable race conditions in this window. First, an attacker mounts a malicious FUSE filesystem over the scratch directory immediately after its creation; because mount-namespace isolation is applied by snap-confine only later in the sequence, the FUSE mount remains externally accessible and can intercept/unmount snap-confine's subsequent operations. Second, when snap-confine opens files in that directory with open(full_path, O_CREAT|O_TRUNC, 0644) without the O_NOFOLLOW flag, an attacker-planted symlink causes the open() call to follow the link and write to an arbitrary attacker-chosen target instead of the intended sandbox file. A further permission-widening race (chmod 0666) can occur before the fchown() ownership transfer completes, extending the writable window.

To turn this arbitrary-write primitive into root code execution, the exploit targets /run/udev/**, a path that AppArmor's snap-confine security profile permits read-write access to. By redirecting the symlink race to write a malicious .rules file into /run/udev/rules.d/ and then triggering a FUSE mount/unmount cycle, the attacker causes systemd-udevd (which runs as root and processes udev events, including RUN+= directives in rule files) to execute an attacker-controlled command with full root privileges — completing the local privilege-escalation chain from unprivileged user to root with no user interaction and low attack complexity.

The flaw affects default installations of Ubuntu Desktop 22.04 LTS, 24.04 LTS, 25.10, and 26.04 running vulnerable snapd releases (approximately snapd 2.75.0 through 2.76.0) that use the set-capabilities snap-confine variant; systems still running the legacy set-uid-root snap-confine configuration are not affected. Qualys TRU (led by Saeed Abbasi) privately disclosed the issue to the Ubuntu Security Team on 2026-04-22; Canonical distributed fixes to the linux-distros coordination list on 2026-07-13 and published a public advisory on 2026-07-14, with full coordinated disclosure and patch release on 2026-07-21 via Ubuntu Security Notice USN-8579-1, which also bundled fixes for two related snapd flaws: CVE-2024-5300 (AppArmor template flaw exposing hashed user passwords via the systemd-userdbd varlink interface, affecting Ubuntu releases back to 16.04 LTS) and CVE-2026-15226 (seccomp template flaw permitting setuid binary creation, enabling escape from confined root to unconfined root). No in-the-wild exploitation or public PoC release has been reported for CVE-2026-8933 as of disclosure; Qualys withheld full working exploit code pending patch adoption. Given that snap is a default packaging format across most modern Ubuntu Desktop and Ubuntu Core installations, and that the vulnerability requires only unprivileged local code execution as a precondition (readily obtainable via a malicious downloaded binary, compromised low-privilege service account, or post-initial-access foothold), this issue warrants priority patching and detection coverage for privilege-escalation chains involving snap-confine, FUSE mounts, and udev rule file writes.

MITRE ATT&CK techniques used in TL-2026-1633

Defense Evasion

T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1211 Exploitation for Stealth; T1564.001 Hide Artifacts: Hidden Files and Directories

Execution

T1059.004 Command and Scripting Interpreter: Unix Shell; T1569 System Services

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1078.003 Valid Accounts: Local Accounts; T1548 Abuse Elevation Control Mechanism; T1548.001 Abuse Elevation Control Mechanism: Setuid and Setgid; T1611 Escape to Host

Discovery

T1082 System Information Discovery; T1518.001 Software Discovery: Security Software Discovery

defense-impairment

T1222.002 Linux and Mac Permissions

Persistence

T1546.017 Event Triggered Execution: Udev Rules

Credential Access

T1552 Unsecured Credentials

Resource Development

T1587.004 Develop Capabilities: Exploits

Affected products and versions in CVE-2026-8933

  • Canonical — snapd / snap-confine (Ubuntu Desktop)
    Vulnerable versions: Ubuntu Desktop 22.04 LTS (snapd < 2.76+ubuntu22.04.1); Ubuntu Desktop 24.04 LTS (snapd < 2.76+ubuntu24.04.1); Ubuntu Desktop 25.10 (snapd, set-capabilities snap-confine variant); Ubuntu Desktop 26.04 (snapd < 2.76+ubuntu26.04.3); snapd 2.75.0 through 2.76.0 (upstream semver range)
    Fixed in: snapd 2.76+ubuntu26.04.3; snapd 2.76+ubuntu24.04.1; snapd 2.76+ubuntu22.04.1; snapd 2.67.1+20.04ubuntu1~esm3 (ESM); snapd 2.61.4ubuntu0.18.04.1+esm4 (ESM); snapd 2.61.4ubuntu0.16.04.1+esm4 (ESM)

Remediation for CVE-2026-8933

Patches

  • snapd 2.76+ubuntu26.04.3 (Ubuntu 26.04 LTS)
  • snapd 2.76+ubuntu24.04.1 (Ubuntu 24.04 LTS)
  • snapd 2.76+ubuntu22.04.1 (Ubuntu 22.04 LTS)
  • snapd 2.67.1+20.04ubuntu1~esm3 (Ubuntu 20.04 LTS, Ubuntu Pro/ESM required)
  • snapd 2.61.4ubuntu0.18.04.1+esm4 (Ubuntu 18.04 LTS, Ubuntu Pro/ESM required)
  • snapd 2.61.4ubuntu0.16.04.1+esm4 (Ubuntu 16.04 LTS, Ubuntu Pro/ESM required)

Immediate actions

  • Update snapd to the patched version for your Ubuntu release via apt update && apt install --only-upgrade snapd
  • Verify installed snapd version explicitly — do not assume patched status from release/update date alone, per Qualys and vendor guidance
  • On systems that cannot patch immediately, restrict local unprivileged account creation/logon and monitor for unexpected FUSE mounts under /tmp

Workarounds

  • No fully effective workaround without patching; where patching is delayed, restrict unprivileged local access and monitor /run/udev/rules.d and /tmp/snap.rootfs_* for anomalous writes

Longer-term hardening

  • Deploy auditd/eBPF-based monitoring for udev rule file writes outside of package-manager-driven changes (auditctl -w /run/udev/rules.d -p wa)
  • Deploy EDR/behavioral detection for mount() syscalls targeting snap-confine scratch directories (/tmp/snap.rootfs_*)
  • Track Canonical/Ubuntu security notices for snapd and apply patches promptly given snapd's default-installed, high-privilege attack surface

CVEs associated with CVE-2026-8933

CVE-2026-8933

Weaknesses (CWE) in CVE-2026-8933

CWE-367, CWE-59, CWE-250, CWE-269, CWE-362

Timeline of CVE-2026-8933

  • Historical related snap-confine flaw 'Oh Snap! More Lemmings' (CVE-2021-44731) disclosed, establishing a recurring pattern of race-condition issues in snap-confine's privileged temp-file handling.
  • CVE-2022-3328 discloses a related snap-confine race condition, combinable with CVE-2021-44731 for privilege escalation — an additional historical precedent in the recurring snap-confine sandbox-initialization bug pattern.
  • Canonical shifts snap-confine from a set-uid-root binary to a set-capabilities model as a security hardening measure, inadvertently introducing the race-condition window later identified as CVE-2026-8933.
  • Related snap-confine/systemd-tmpfiles race condition CVE-2026-3888 (CVSS 7.8) disclosed by Qualys, involving a similar cleanup-window privilege escalation; public PoC later published on GitHub.
  • Qualys Threat Research Unit privately discloses the snap-confine race-condition vulnerability to the Ubuntu Security Team.
  • Canonical distributes patches to the coordinated linux-distros disclosure mailing list ahead of public release.
  • Initial public advisory information for the snapd fixes becomes available.
  • Ubuntu publishes the official CVE-2026-8933 tracking page confirming Jammy/Noble/Resolute as fixed and Focal/Bionic/Xenial as not affected.
  • Qualys Threat Research Unit (Saeed Abbasi) publishes full technical writeup and advisory for CVE-2026-8933, detailing the FUSE/symlink/udev exploit chain.
  • Canonical publishes a companion Ubuntu Discourse post ('Snapd - multiple vulnerabilities fixed') summarizing the three bundled CVEs, listing per-release package versions, and instructing users that a system reboot is required after updating snapd.
  • Canonical publishes Ubuntu Security Notice USN-8579-1, releasing fixed snapd packages for Ubuntu 16.04 through 26.04 LTS and formally assigning CVE-2026-8933 alongside CVE-2024-5300 and CVE-2026-15226.
  • As of this date, CVE-2026-8933 has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog and no confirmed in-the-wild exploitation has been reported; risk is driven by public PoC availability and broad default-install impact.
  • The Hacker News, Infosecurity Magazine, Phoronix, and other outlets publish coverage summarizing the vulnerability and urging patch adoption.
  • Runtime-security vendor Exein publishes a detection write-up (Exein Photon) mapping the vulnerable open()-without-O_NOFOLLOW pattern to a blockable eBPF rule.

Update history for TL-2026-1633

Sources cited for CVE-2026-8933

Detection coverage for TL-2026-1633

As of 2026-07-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1633 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
29 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats