216.73.216.6

CVE-2026-3888

· Published 17/03/2026 14:16 · Modified 18/03/2026 04:17

Labels: CVE-2026-3888 2026-03-17CVE-2026-3888CWE-268[email protected]

Essential information

Published
17/03/2026 14:16
Modified
18/03/2026 04:17
Author
Creator
CVSS
7.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
ubuntu / snapd cpe:2.3:a:ubuntu:snapd:16.04:*:*:*:*:*:*:*
ubuntu / snapd cpe:2.3:a:ubuntu:snapd:18.04:*:*:*:*:*:*:*
ubuntu / snapd cpe:2.3:a:ubuntu:snapd:20.04:*:*:*:*:*:*:*
ubuntu / snapd cpe:2.3:a:ubuntu:snapd:22.04:*:*:*:*:*:*:*
ubuntu / snapd cpe:2.3:a:ubuntu:snapd:24.04:*:*:*:*:*:*:*

References