CVE-2026-3888CWE-268

Local Privilege Escalation in snapd

High · published March 17, 2026

CVSS v3.1
7.8
EPSS
0%
Percentile
31.4
In the wild
Unconfirmed
What it is

Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.

The record
Technical detail
CVSS v3.1
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00383 · 31.4th percentile
Weakness
CWE-268 · Privilege Chaining
Published
2026-03-17T14:02Z
EPSS history
Timeline
  • 17 MAR 14:02Z
    Local Privilege Escalation in snapd
    cvelistv5