CVE-2026-3888
Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.
- Affected products
- Linuxmint, Ubuntu, Snapd, Uutils Coreutils
- Canonical Ubuntu Linux
- = 16.04, 18.04, 20.04, 22.04, 24.04
- Fix
- Available
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 0.4% (32th percentile)
- Weakness
- CWE-268
- NVD status
- Analyzed
- Published
- 2026-03-17
- Attack patterns
- CAPEC-233
CVE-2026-3888 at NVD
7 known exploits for CVE-2026-3888
Proof-of-concept code and exploit modules indexed by Sploitus
web-management-server-compromise-assessment
Exploit for CVE-2026-3888
Exploit for Missing Authentication for Critical Function in Nginxui Nginx_Ui
Exploit for Missing Authentication for Critical Function in Nginxui Nginx_Ui
Exploit for CVE-2026-3888
Exploit for CVE-2026-3888
Exploit for CVE-2026-3888