CVE-2026-3888
published 2026-03-17CVE-2026-3888: Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is…
PriorityP344high7.8CVSS 3.1
AVLACHPRLUINSCCHIHAH
EPSS
0.38%
30.6th percentile
Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | snapd | < snapd 2.57.6-1+deb12u1 (bookworm) | snapd 2.57.6-1+deb12u1 (bookworm) |
| snapcraft | snapd | >= 0 < 2.57.6-1+deb12u1 | 2.57.6-1+deb12u1 |
| snapcraft | snapd | >= 0 < 2.68.3-3+deb13u1 | 2.68.3-3+deb13u1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2026-3888: Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tm
osv·2026-03-17·CVSS 7.8
CVE-2026-3888 [HIGH] CVE-2026-3888: Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tm
Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.
GHSA
GHSA-grpw-jgrw-ccqr: Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tm
ghsa_unreviewed·2026-03-17
CVE-2026-3888 [HIGH] CWE-268 GHSA-grpw-jgrw-ccqr: Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tm
Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.
Ubuntu
snapd vulnerability
vendor_ubuntu·2026-03-17
CVE-2026-3888 snapd vulnerability
Title: snapd vulnerability
Summary: snapd could be used to escalate privilege
Qualys discovered that snapd incorrectly handled certain operations in the
snap's private /tmp directory. If systemd-tmpfiles is enabled to automatically
clean up this directory, a local attacker could possibly use this issue to
re-create the deleted directory, resulting in privilege escalation.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
snapd regression
vendor_ubuntu·2026-03-17
CVE-2026-3888 snapd regression
Title: snapd regression
Summary: USN-8102-1 introduced a regression in snapd
USN-8102-1 fixed a vulnerability in snapd. The update caused a regresision for
Ubuntu 24.04 LTS while installing the package. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Qualys discovered that snapd incorrectly handled certain operations in the
snap's private /tmp directory. If systemd-tmpfiles is enabled to automatically
clean up this directory, a local attacker could possibly use this issue to
re-create the deleted directory, resulting in privilege escalation.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Debian
CVE-2026-3888: snapd - Local privilege escalation in snapd on Linux allows local attackers to get root ...
vendor_debian·2026·CVSS 7.8
CVE-2026-3888 [HIGH] CVE-2026-3888: snapd - Local privilege escalation in snapd on Linux allows local attackers to get root ...
Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.
Scope: local
bookworm: resolved (fixed in 2.57.6-1+deb12u1)
bullseye: open
forky: open
sid: open
trixie: resolved (fixed in 2.68.3-3+deb13u1)
No public exploits indexed.
Hackernews
⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More
blogs_hackernews·2026-03-23
⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More
Another week, another reminder that the internet is still a mess. Systems people thought were secure are being broken in simple ways, showing many still ignore basic advisories.
This edition covers a mix of issues: supply chain attacks hitting CI/CD setups, long-abused IoT devices being shut down, and exploits moving quickly from disclosure to real attacks. There are also new malware tricks showing attackers are becoming more patient and creative.
It’s a mix of old problems that never go away and new methods that are harder to detect. Th
Qualys
CVE-2026-3888: Important Snap Flaw Enables Local Privilege Escalation to Root | Qualys
blogs_qualys·2026-03-17·CVSS 7.8
CVE-2026-3888 [HIGH] CVE-2026-3888: Important Snap Flaw Enables Local Privilege Escalation to Root | Qualys
#### Table of Contents
- What is the attack surface for CVE-2026-3888?
- Exploitation Mechanism:
- Affected Versions & Remediation
- Technical Details
- Secondary Finding: Vulnerability in Ubuntu 25.10 uutils Coreutils
- Qualys QID Coverage for Detecting theCVE-2026-3888:
- Discover Vulnerable Assets with Qualys CyberSecurity Asset Management
- Enhancing Your Security Posture with Qualys VMDR to Detect and Remediate the CVE-2026-3888 Vulnerability
- Automatically Patch CVE-2026-3888 with Qualys Patch Management
The Qualys Threat Research Unit has identified a Local Privilege Escalation (LPE) vulnerability affecting default installations of Ubuntu Desktop version 24.04 and later. This flaw (CVE-2026-3888) allows an unprivileged local attacker to escalate privileges to full root access thr
Qualys
CVE-2026-3888: Important Snap Flaw Enables Local Privilege Escalation to Root
blogs_qualys·2026-03-17·CVSS 7.8
CVE-2026-3888 [HIGH] CVE-2026-3888: Important Snap Flaw Enables Local Privilege Escalation to Root
## Table of Contents
What is the attack surface for CVE-2026-3888?
Exploitation Mechanism:
Affected Versions & Remediation
Technical Details
Secondary Finding: Vulnerability in Ubuntu 25.10 uutils Coreutils
Qualys QID Coverage for Detecting theCVE-2026-3888:
Discover Vulnerable Assets with Qualys CyberSecurity Asset Management
Enhancing Your Security Posture with Qualys VMDR to Detect and Remediate the CVE-2026-3888 Vulnerability
Automatically Patch CVE-2026-3888 with Qualys Patch Management
The Qualys Threat Research Unit has identified a Local Privilege Escalation (LPE) vulnerability affecting default installations of Ubuntu Desktop version 24.04 and later. This flaw (CVE-2026-3888) allows an unprivileged local attacker to escalate privileges to full root access through the int
Wiz
CVE-2026-3888 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-3888 [MEDIUM] CVE-2026-3888 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3888 :
Linux Debian vulnerability analysis and mitigation
Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.
Source : NVD
## 7.8
Score
Published March 17, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Linux Debian
Linux Ubuntu
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
snapd
Sources
NVD
Debian 11, 14 Severity HIGH No Fix Added at: Mar 17,
https://blog.qualys.com/vulnerabilities-threat-research/2026/03/17/cve-2026-3888-important-snap-flaw-enables-local-privilege-escalation-to-roothttps://cdn2.qualys.com/advisory/2026/03/17/snap-confine-systemd-tmpfiles.txthttps://discourse.ubuntu.com/t/snapd-local-privilege-escalation-cve-2026-3888https://ubuntu.com/security/CVE-2026-3888https://ubuntu.com/security/notices/USN-8102-1http://www.openwall.com/lists/oss-security/2026/03/18/1
2026-03-17
Published