logo

CVE-2026-3888: Important Snap Flaw Enables Local Privilege Escalation to Root

ID: f46e2608-1c11-5fb3-bf99-d8453b596c33

STIX ID: report--f46e2608-1c11-5fb3-bf99-d8453b596c33

Feed Name: Qualys Blog

Threat Score
75/100

Date Published: 2026-03-17

Date Updated: 2026-04-28

Author: Saeed Abbasi

...
...

**Executive Summary:** Qualys Threat Research Unit disclosed CVE-2026-3888, a high-severity local privilege escalation in snap-confine combined with systemd-tmpfiles on Ubuntu Desktop (default installs of 24.04 and later) that can allow an unprivileged user to gain root by exploiting a time-based /tmp cleanup window; affected snapd versions and patched releases are listed and immediate upgrades are recommended. The report also notes a separately discovered race condition in the uutils coreutils 'rm' utility that was mitigated before Ubuntu 25.10 release.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.