CVE-2026-3888 - Vulnerability Analysis
HighCVSS: 7.8Last Updated: March 18, 2026
snapd - Privilege Escalation
Overview
snapd on Linux (Ubuntu 16.04 LTS to 24.04 LTS) contains a local privilege escalation caused by re-creation of snap's private /tmp directory during systemd-tmpfiles cleanup, letting local attackers gain root privileges.
Severity & Score
Impact
Local attackers can gain root privileges, fully compromising the system.
Mitigation
Update to the latest snapd version with the fix applied.
References
- https://discourse.ubuntu.com/t/snapd-local-privilege-escalation-cve-2026-3888
- https://ubuntu.com/security/notices/USN-8102-1
- http://www.openwall.com/lists/oss-security/2026/03/18/1
- https://ubuntu.com/security/CVE-2026-3888
- https://blog.qualys.com/vulnerabilities-threat-research/2026/03/17/cve-2026-3888-important-snap-flaw-enables-local-privilege-escalation-to-root
- https://cdn2.qualys.com/advisory/2026/03/17/snap-confine-systemd-tmpfiles.txt
Social Media Activity(21 posts)
π° Today's Top 20 Hacker News Stories (Sorted by Score) π° ---------------------------------------- π Title: Rob Pike's Rules of Programming (1989) π URL: https://www.cs.unc.edu/~stotts/COMP590-059-f24/robsrules.html π Score: [699] π¬ Discussion: https://news.ycombinator.com/item?id=47423647 ---------------------------------------- π Title: Nightingale β open-source karaoke app that works with any song on your computer π URL: https://nightingale.cafe/ π Score: [414] π¬ Discussion: https://news.ycombinator.com/item?id=47422942 ---------------------------------------- π Title: Federal Cyber Experts Called Microsoft's Cloud "A Pile of Shit", yet Approved It π URL: https://www.propublica.org/article/microsoft-cloud-fedramp-cybersecurity-government π Score: [360] π¬ Discussion: https://news.ycombinator.com/item?id=47426057 ---------------------------------------- π Title: Death to Scroll Fade π URL: https://dbushell.com/2026/01/09/death-to-scroll-fade/ π Score: [276] π¬ Discussion: https://news.ycombinator.com/item?id=47426932 ---------------------------------------- π Title: The pleasures of poor product design π URL: https://www.inconspicuous.info/p/the-pleasures-of-poor-product-design π Score: [232] π¬ Discussion: https://news.ycombinator.com/item?id=47420432 ---------------------------------------- π Title: Write up of my homebrew CPU build π URL: https://willwarren.com/2026/03/12/building-my-own-cpu-part-3-from-simulation-to-hardware/ π Score: [209] π¬ Discussion: https://news.ycombinator.com/item?id=47389696 ---------------------------------------- π Title: AI coding is gambling π URL: https://notes.visaint.space/ai-coding-is-gambling/ π Score: [196] π¬ Discussion: https://news.ycombinator.com/item?id=47428541 ---------------------------------------- π Title: Snowflake AI Escapes Sandbox and Executes Malware π URL: https://www.promptarmor.com/resources/snowflake-ai-escapes-sandbox-and-executes-malware π Score: [179] π¬ Discussion: https://news.ycombinator.com/item?id=47427017 ---------------------------------------- π Title: OpenRocket π URL: https://openrocket.info/ π Score: [164] π¬ Discussion: https://news.ycombinator.com/item?id=47386703 ---------------------------------------- π Title: Show HN: Hacker News archive (47M+ items, 11.6GB) as Parquet, updated every 5m π URL: https://huggingface.co/datasets/open-index/hacker-news π Score: [148] π¬ Discussion: https://news.ycombinator.com/item?id=47378781 ---------------------------------------- π Title: Nvidia NemoClaw π URL: https://github.com/NVIDIA/NemoClaw π Score: [138] π¬ Discussion: https://news.ycombinator.com/item?id=47427027 ---------------------------------------- π Title: Celebrating Tony Hoare's mark on computer science π URL: https://bertrandmeyer.com/2026/03/16/celebrating-tony-hoares-mark-on-computer-science/ π Score: [108] π¬ Discussion: https://news.ycombinator.com/item?id=47422228 ---------------------------------------- π Title: Machine Payments Protocol (MPP) π URL: https://stripe.com/blog/machine-payments-protocol π Score: [98] π¬ Discussion: https://news.ycombinator.com/item?id=47426936 ---------------------------------------- π Title: Using calculus to do number theory π URL: https://hidden-phenomena.com/articles/hensels π Score: [78] π¬ Discussion: https://news.ycombinator.com/item?id=47399330 ---------------------------------------- π Title: Google Engineers Launch "Sashiko" for Agentic AI Code Review of the Linux Kernel π URL: https://www.phoronix.com/news/Sashiko-Linux-AI-Code-Review π Score: [62] π¬ Discussion: https://news.ycombinator.com/item?id=47427647 ---------------------------------------- π Title: Wander β A tiny, decentralised tool (just 2 files) to explore the small web π URL: https://susam.net/wander/ π Score: [56] π¬ Discussion: https://news.ycombinator.com/item?id=47427290 ---------------------------------------- π Title: A ngrok-style secure tunnel server written in Rust and Open Source π URL: https://github.com/joaoh82/rustunnel π Score: [50] π¬ Discussion: https://news.ycombinator.com/item?id=47425918 ---------------------------------------- π Title: 2025 Turing award given for quantum information science π URL: https://awards.acm.org/about/2025-turing π Score: [48] π¬ Discussion: https://news.ycombinator.com/item?id=47423694 ---------------------------------------- π Title: Wanter β A tiny, decentralised tool to explore the small web π URL: https://susam.net/wander/ π Score: [44] π¬ Discussion: https://news.ycombinator.com/item?id=47422759 ---------------------------------------- π Title: CVE-2026-3888: Important Snap Flaw Enables Local Privilege Escalation to Root π URL: https://blog.qualys.com/vulnerabilities-threat-research/2026/03/17/cve-2026-3888-important-snap-flaw-enables-local-privilege-escalation-to-root π Score: [33] π¬ Discussion: https://news.ycombinator.com/item?id=47427208 ----------------------------------------
View original postCVE-2026-3888 en #Ubuntu: escalada a root aprovechando snap-confine y la limpieza de systemd-tmpfiles https://unaaldia.hispasec.com/2026/03/cve-2026-3888-en-ubuntu-escalada-a-root-aprovechando-snap-confine-y-la-limpieza-de-systemd-tmpfiles.html?utm_source=rss&
View original postUbuntu CVE-2026-3888 Bug Lets Attackers Gain Root via systemd Cleanup Timing Exploit https://thehackernews.com/2026/03/ubuntu-cve-2026-3888-bug-lets-attackers.html Short summary: https://hackerworkspace.com/article/ubuntu-cve-2026-3888-bug-lets-attackers-gain-root-via-systemd-cleanup-timing-exploit #cybersecurity #vulnerability #exploit
View original postAlerte pour les bubuntuistes: https://thehackernews.com/2026/03/ubuntu-cve-2026-3888-bug-lets-attackers.html
View original postiOS/iPadOS 26.4 RC, GNOME 50 βTokyo,β and FFmpeg 8.1. - Linux security flaws (CVE-2026-3888) and open-source alternatives (e.g., Ageless Linux). 5. **Hardware & Gadgets** - Samsung Galaxy Z TriFold discontinuation, BYDβs 1,500km solid-state battery, and Tesla Cybertruck safety concerns. - Framework 16β laptop issues and retro computing (e.g., Commodore 64). [3/3]
View original postCVE-2026-3888: Important Snap Flaw Enables Local Privilege Escalation to Root #CVE_2026_3888 https://blog.qualys.com/vulnerabilities-threat-research/2026/03/17/cve-2026-3888-important-snap-flaw-enables-local-privilege-escalation-to-root
View original postGlobal tensions heighten as the US-Iran conflict escalates, impacting oil markets via the Strait of Hormuz (March 18). Technology sees continued rapid AI advancement, with OpenAI's GPT-5.4 and Anthropic's Claude Sonnet 4.6 released (March 17). In cybersecurity, the EU sanctioned private cyber offensive groups (March 17), and a critical Ubuntu privilege escalation flaw (CVE-2026-3888) was discovered (March 18). AI-driven threats also increasingly impact M&A security. #Geopolitics #Cybersecurity #AINews
View original postUbuntu CVE-2026-3888 Bug Lets Attackers Gain Root via systemd Cleanup Timing Exploit https://thehackernews.com/2026/03/ubuntu-cve-2026-3888-bug-lets-attackers.html
View original postCritical Ubuntu flaw (CVE-2026-3888) enables local root escalation via Snap. Delayed exploit (10β30 days) makes detection harder. Patch snapd immediately. https://www.technadu.com/critical-cve-2026-3888-vulnerability-exposes-ubuntu-to-root-escalation/623670/ #Cybersecurity #Linux #Ubuntu
View original postCVE-2026-3888: Ubuntu Desktop 24.04+ vulnerable to Root exploit https://securityaffairs.com/189614/security/cve-2026-3888-ubuntu-desktop-24-04-vulnerable-to-root-exploit.html
View original post[lien] https://www.it-connect.fr/cve-2026-3888-quand-le-nettoyage-systeme-dubuntu-offre-un-acces-root/ #security #gik #deb #wtf
View original postCVE-2026-3888 : quand le nettoyage systΓ¨me dβUbuntu offre un accΓ¨s root https://www.it-connect.fr/cve-2026-3888-quand-le-nettoyage-systeme-dubuntu-offre-un-acces-root/ #ActuCybersΓ©curitΓ© #CybersΓ©curitΓ© #VulnΓ©rabilitΓ© #Linux
View original postUbuntu CVE-2026-3888 Bug Lets Attackers Gain Root via systemd Cleanup Timing Exploit https://thehackernews.com/2026/03/ubuntu-cve-2026-3888-bug-lets-attackers.html
View original postUbuntu CVE-2026-3888 Bug Lets Attackers Gain Root via systemd Cleanup Timing Exploit https://thehackernews.com/2026/03/ubuntu-cve-2026-3888-bug-lets-attackers.html Short summary: https://hackerworkspace.com/article/ubuntu-cve-2026-3888-bug-lets-attackers-gain-root-via-systemd-cleanup-timing-exploit #cybersecurity #vulnerability #exploit
View original postCVE-2026-3888: Important Snap Flaw Enables Local Privilege Escalation to Root #CVE_2026_3888 https://blog.qualys.com/vulnerabilities-threat-research/2026/03/17/cve-2026-3888-important-snap-flaw-enables-local-privilege-escalation-to-root
View original postGlobal tensions heighten as the US-Iran conflict escalates, impacting oil markets via the Strait of Hormuz (March 18). Technology sees continued rapid AI advancement, with OpenAI's GPT-5.4 and Anthropic's Claude Sonnet 4.6 released (March 17). In cybersecurity, the EU sanctioned private cyber offensive groups (March 17), and a critical Ubuntu privilege escalation flaw (CVE-2026-3888) was discovered (March 18). AI-driven threats also increasingly impact M&A security. #Geopolitics #Cybersecurity #AINews
View original postUbuntu CVE-2026-3888 Bug Lets Attackers Gain Root via systemd Cleanup Timing Exploit https://thehackernews.com/2026/03/ubuntu-cve-2026-3888-bug-lets-attackers.html
View original postCritical Ubuntu flaw (CVE-2026-3888) enables local root escalation via Snap. Delayed exploit (10β30 days) makes detection harder. Patch snapd immediately. https://www.technadu.com/critical-cve-2026-3888-vulnerability-exposes-ubuntu-to-root-escalation/623670/ #Cybersecurity #Linux #Ubuntu
View original postCVE-2026-3888: Ubuntu Desktop 24.04+ vulnerable to Root exploit https://securityaffairs.com/189614/security/cve-2026-3888-ubuntu-desktop-24-04-vulnerable-to-root-exploit.html
View original postCVE-2026-3888 : quand le nettoyage systΓ¨me dβUbuntu offre un accΓ¨s root https://www.it-connect.fr/cve-2026-3888-quand-le-nettoyage-systeme-dubuntu-offre-un-acces-root/ #ActuCybersΓ©curitΓ© #CybersΓ©curitΓ© #VulnΓ©rabilitΓ© #Linux
View original postπ CVE-2026-3888 - High (7.8) Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LT... π https://www.thehackerwire.com/vulnerability/CVE-2026-3888/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postGitHub Repositories(1 repo)
Related Resources
Details
- CVE ID
- CVE-2026-3888
- Severity
- High
- CVSS Score
- 7.8
- Type
- broken_access_control
- Status
- unconfirmed
- EPSS
- 0.6%
- Social Posts
- 21
CWE
- CWE-268
CVSS Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H