# CVE-2026-3888

## Summary

- **CVE ID:** CVE-2026-3888
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-268
- **Published:** Mar 17, 2026
- **Last Modified:** Mar 19, 2026

## Description

Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.

## Affected Products

- Unknown product (0)
- Canonical — Ubuntu 16.04 LTS (2.61.4ubuntu0.16.04.1+esm2)
- Canonical — Ubuntu 18.04 LTS (2.61.4ubuntu0.18.04.1+esm2)
- Canonical — Ubuntu 20.04 LTS (2.67.1+20.04ubuntu1~esm1)
- Canonical — Ubuntu 22.04 LTS (2.73+ubuntu22.04.1)
- Canonical — Ubuntu 24.04 LTS (2.73+ubuntu24.04.1)
- Canonical — Ubuntu 24.04 LTS (2.73+ubuntu24.04.2)

## References

- [CNA](https://ubuntu.com/security/CVE-2026-3888)
- [CNA](https://ubuntu.com/security/notices/USN-8102-1)
- [CNA](https://discourse.ubuntu.com/t/snapd-local-privilege-escalation-cve-2026-3888)
- [CNA](https://blog.qualys.com/vulnerabilities-threat-research/2026/03/17/cve-2026-3888-important-snap-flaw-enables-local-privilege-escalation-to-root)
- [CNA](https://cdn2.qualys.com/advisory/2026/03/17/snap-confine-systemd-tmpfiles.txt)
- [CVE](http://www.openwall.com/lists/oss-security/2026/03/18/1)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.38%
- **EPSS Percentile:** 31.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-12._