Ubuntu Desktop systems running version 24.04 and later are exposed to a new local privilege escalation vulnerability, CVE-2026-3888, that allows a low-privileged user to gain full root access by abusing how snapd and systemd manage temporary directories.
The flaw affects default desktop installations and turns a seemingly low-risk local account into a complete system compromise if left unpatched.
CVE-2026-3888 is a High-severity local privilege escalation in snapd, the service that manages Snap packages on Ubuntu, with a CVSS v3.1 score of 7.8.
It arises from an unintended interaction between the snap-confine helper (a setuid-root binary that prepares Snap sandboxes) and systemd-tmpfiles, which periodically cleans temporary directories.
When combined, these two otherwise secure components create a scenario where an unprivileged attacker can hijack Snap’s private temporary directory and ride snap-confine’s privileged operations to root.

How the exploit works
The attack relies on the periodic cleanup of the snap private temporary directory and careful timing by the attacker.
On affected Ubuntu Desktop systems, systemd-tmpfiles is configured to delete stale data in /tmp after 30 days on Ubuntu 24.04 and 10 days on newer releases, including the critical /tmp/.snap directory used by snap-confine.
Once this directory is removed, a local attacker can recreate it and populate it with malicious content; during the next Snap sandbox initialization, snap-confine bind-mounts attacker-controlled files as root, resulting in arbitrary code execution with full root privileges.
Impact on Ubuntu environments
The vulnerability impacts default installations of Ubuntu Desktop 24.04 and later, where snapd and systemd-tmpfiles are enabled, meaning a normal local user account can eventually obtain unrestricted root control of the host.
Although the time-based nature of the exploit (10–30 day window) raises attack complexity, it does not meaningfully reduce the risk in long-lived desktop or developer systems that remain powered on and in regular use.
Once exploited, an attacker can disable security tools, install persistent malware, exfiltrate sensitive data, or pivot into containers and Kubernetes workloads managed from the compromised workstation.
Ubuntu lists CVE-2026-3888 as a fixed snapd issue, with patched packages released across supported versions.
Organizations should ensure snapd is updated at least to 2.73+ubuntu24.04.1 on Ubuntu 24.04 LTS and equivalent 2.73+ or later builds on Ubuntu 25.10 and 26.04 development branches, while upstream snapd users should move to version 2.75 or newer.
Even older Ubuntu LTS releases (16.04–22.04) that are not vulnerable in default configurations are advised to apply available updates to avoid risk from customized tmpfiles or snap setups that mimic newer behavior.
During the same review, researchers also identified a race condition in Ubuntu 25.10’s Rust-based uutils coreutils implementation of rm that could be abused during root cron jobs to delete arbitrary files or escalate privileges, leading Ubuntu to revert to GNU coreutils and ship upstream fixes.
For defenders, Qualys has assigned QID 386810 to detect CVE-2026-3888 in vulnerability scans, and Ubuntu’s official CVE and security notice entries provide authoritative tracking for patch status across releases.
Security teams should combine OS patching with regular snapd updates and monitoring of /tmp cleanup policies to ensure similar privilege-chaining issues are not reintroduced in future configurations.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google