Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.
https://ubuntu.com/security/notices/USN-8102-1
https://ubuntu.com/security/CVE-2026-3888
https://discourse.ubuntu.com/t/snapd-local-privilege-escalation-cve-2026-3888
https://thehackernews.com/2026/07/ubuntu-snap-confine-flaw-could-give.html
https://www.infosecurity-magazine.com/news/ubuntu-flaw-enables-root-access/
https://thehackernews.com/2026/03/ubuntu-cve-2026-3888-bug-lets-attackers.html
https://github.com/Cosm3No1de/HTB-Snapped-Writeup
https://github.com/ridhinva/hermes-vuln-tools
https://github.com/Ruby570bocadito/CVE-ubuntu-server-24.04
https://github.com/hewhomusntbenamed/CVE-2026-3888-fixed
https://github.com/karimelsheikh1/HTB-Snapped-Writeup
https://github.com/nomaisthere/CVE-2026-3888
https://github.com/TheCyberGeek/CVE-2026-3888-snap-confine-systemd-tmpfiles-LPE
https://github.com/netw0rk7/CVE-2026-3888-PoC
https://github.com/Many-Hat-Group/Ubuntu-CVE-2026-3888-patcher