CVE-2026-3888Disclosure(canonical / ubuntu_linux)

CRITICALCVSS 7.8 · HIGH

Exploitation observed; activity peaked at 94 mentions and remains active

Immediate actions

  • Patch canonical ubuntu_linux systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-268

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ubuntu_linux

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 196 mentions across 21 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 16 signals
  • Patch or workaround mentioned in 45 signals
  • Technical details provided in 153 signals
  • Disclosure: 114 classified signals
  • General: 36 classified signals
  • Peaked 19d ago at 94 mentions (2026-03-18); latest day: 2
  • 196 total mentions across 21 days

Affected systems

Vendors
Products
ubuntu_linux

5 versions affected across 1 product

Deep dive

Activity timeline196 mentions / 21d
024477194Mentions · 2026-03-17: 12Mentions · 2026-03-18: 94Mentions · 2026-03-19: 34Mentions · 2026-03-20: 11Mentions · 2026-03-21: 10Mentions · 2026-03-22: 2Mentions · 2026-03-23: 6Mentions · 2026-03-24: 1Mentions · 2026-03-25: 3Mentions · 2026-03-26: 5Mentions · 2026-03-27: 3Mentions · 2026-03-30: 1Mentions · 2026-04-01: 4Mentions · 2026-04-02: 1Mentions · 2026-04-04: 2Mentions · 2026-04-20: 1Mentions · 2026-04-22: 1Mentions · 2026-04-23: 1Mentions · 2026-05-11: 1Mentions · 2026-05-12: 1Mentions · 2026-05-13: 2PoC Mentioned / Linked · 2026-03-18: 10PoC Mentioned / Linked · 2026-03-23: 2PoC Mentioned / Linked · 2026-03-25: 1PoC Mentioned / Linked · 2026-04-01: 1PoC Mentioned / Linked · 2026-05-11: 1PoC Mentioned / Linked · 2026-05-13: 1Exploit Tool / Code · 2026-03-18: 2Exploit Tool / Code · 2026-03-23: 1Exploit Tool / Code · 2026-03-25: 1Active Exploitation · 2026-03-17: 1Active Exploitation · 2026-03-18: 1Active Exploitation · 2026-03-19: 1Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-03-18: 26Patch / Workaround · 2026-03-19: 7Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-21: 5Patch / Workaround · 2026-03-22: 1Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-17: 10Technical Details · 2026-03-18: 77Technical Details · 2026-03-19: 22Technical Details · 2026-03-20: 7Technical Details · 2026-03-21: 8Technical Details · 2026-03-22: 2Technical Details · 2026-03-23: 5Technical Details · 2026-03-24: 1Technical Details · 2026-03-25: 3Technical Details · 2026-03-26: 3Technical Details · 2026-03-27: 3Technical Details · 2026-03-30: 1Technical Details · 2026-04-01: 4Technical Details · 2026-04-02: 1Technical Details · 2026-04-04: 1Technical Details · 2026-04-20: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-13: 203-1703-1903-2103-2303-2503-2704-0104-0404-2205-1105-13
Signal classification6 categories
Disclosure
11458.2%
General
3618.4%
Patch
3115.8%
PoC
73.6%
Exploit
52.6%
Active Exploitation
31.5%
Referenced assets104 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-1712
Active Exploitation1Disclosure7General3Patch1
2026-03-1894
Active Exploitation1Disclosure58Exploit2General10Patch20PoC3
2026-03-1934
Active Exploitation1Disclosure21General9Patch3
2026-03-2011
Disclosure8General3
2026-03-2110
Disclosure5General1Patch4
2026-03-222
Disclosure2
2026-03-236
General3Patch1PoC2
2026-03-241
Disclosure1
2026-03-253
Disclosure2Exploit1
2026-03-265
Disclosure2General2Patch1
2026-03-273
Disclosure2Patch1
2026-03-301
Disclosure1
2026-04-014
Disclosure2Exploit2
2026-04-021
Disclosure1
2026-04-042
General2
2026-04-201
Disclosure1
2026-04-221
General1
2026-04-231
General1
2026-05-111
PoC1
2026-05-121
General1
2026-05-132
Disclosure1PoC1
Full discourse20 posts
  • Devuan GNU/Linux@DevuanOrg
    Disclosure

    Found yet another high severity systemd bug in Ubuntu: local root privilege escalation (CVE-2026-3888) https://cybersecurity88.com/news/ubuntu-cve-2026-3888-timing-flaw-in-systemd-cleanup-enables-root-privilege-escalation/ Let us wish all Devuan users a wonderful day out with their family for a merry father's day, instead of showeling unicorn shit. https://t.co/rg8kQbjOIu

    Post summary

    The tweet announces the discovery of a high‑severity local root privilege escalation flaw in Ubuntu’s systemd (CVE‑2026‑3888) with no mention of a PoC, exploit, or patch.

    2311576815016.6K
    6.4K followersView on X
  • yousukezan@yousukezan
    Disclosure

    Ubuntu標準環境に、一般ユーザーからroot権限を奪取できる重大な欠陥が見つかった。特定条件下で時間差を利用しシステムを完全支配できる可能性があり、広範な環境に影響が及ぶ。 CVE-2026-3888はUbuntu Desktop 24.04以降に影響する権限昇格脆弱性で、snap-confineとsystemd-tmpfilesの相互作用に起因する。systemd-tmpfilesは古い/tmp領域を一定期間後に削除するが、このタイミングを攻撃者が悪用する。まず/tmp/.snapディレクトリが自動削除されるのを待ち、攻撃者が同名ディレクトリを悪意ある内容で再作成する。その後、snap-confineがサンドボックス初期化時にこれをroot権限でバインドマウントし、任意コード実行が成立する。攻撃には低権限で十分だが、削除周期(10〜30日)に依存するため時間的条件が必要となる。またuutils coreutilsの競合状態により、cron実行中にシンボリックリンクを差し替える追加の権限昇格経路も確認された。修正はsnapd更新などで提供されている。 https://thehackernews.com/2026/03/ubuntu-cve-2026-3888-bug-lets-attackers.html

    Post summary

    The article details a new Ubuntu privilege‑escalation flaw (CVE‑2026‑3888) that exploits timing in systemd‑tmpfiles and snap‑confine, and notes that a patch is available through snapd updates.

    1164833111334.7K
    12.0K followersView on X
  • The Hacker News@TheHackersNews
    Exploit

    🛑 ALERT - A new flaw in #Ubuntu 24.04+ lets attackers gain full root access from low privileges. By timing system cleanup, they replace a snap directory and execute code as root—no user action required. 🔗 Exploit steps and patched versions → https://thehackernews.com/2026/03/ubuntu-cve-2026-3888-bug-lets-attackers.html

    Post summary

    CVE‑2026‑3888 is a new Ubuntu 24.04+ flaw that lets low‑privilege users gain full root via snap directory replacement; exploit steps and patched versions are linked.

    131171034711027.6K
    1.1M followersView on X
  • Ubuntu@ubuntu
    Patch

    The Ubuntu Security Team and Snapd teams have published fixes for the 7.8 CVSS score CVE-2026-3888. Read how to address: https://discourse.ubuntu.com/t/snapd-local-privilege-escalation-cve-2026-3888/78627

    Post summary

    Ubuntu and Snapd have released patches for CVE‑2026‑3888, a local privilege‑escalation flaw with a 7.8 CVSS score, and provide instructions on how to apply the fix.

    63911312111.9K
    697.4K followersView on X
  • NullSecurityX@NullSecurityX
    PoC

    NEW Videoo: CVE-2026-3888: Nginx-UI Backup Leak to Root Shell + CVE-2026-27944 Snap Copy-Fail Root New video covering a full Linux exploitation chain: Unauth API → Backup leak → Credential cracking → SSH → Snapd TOCTOU privesc → Root shell https://youtu.be/ViyT7bu-ZxE

    Post summary

    A new video demonstrates a complete exploitation chain for CVE-2026-3888 and CVE-2026-27944, showing how attackers can obtain a root shell via unauthenticated backup leaks and a Snapd race condition.

    011050226.7K
    12.3K followersView on X
  • Hack The Box@hackthebox_eu
    General

    New threats alert 🚨  Our latest Machine just dropped on HTB Labs and the Enterprise Platform, challenging you to chain two critical, newly disclosed vulnerabilities. You will first exploit CVE-2026-27944 to gain a foothold via an authentication bypass in Nginx UI, before leveraging a timing-based logic flaw in Ubuntu’s snapd (CVE-2026-3888) to escalate your privileges to root. Sharpen your skills on the new Machine here: https://okt.to/zUtK7u #HackTheBox #Cybersecurity #Nginx #Ubuntu #CVEs #Pentesting #LPE

    Post summary

    The announcement introduces a new HackTheBox machine that challenges users to chain two newly disclosed vulnerabilities—an authentication bypass in Nginx and a timing‑based logic flaw in Ubuntu's snapd—to achieve privilege escalation.

    07064114.0K
    242.0K followersView on X
  • Melko@MelkoXMR
    General

    Oh la privesc de dingue sur Ubuntu 24.04 mdrrrr Si vous avez accès à des machines pendant 10 à 30 jours consécutifs vous pouvez rooter en 3 clics https://thehackernews.com/2026/03/ubuntu-cve-2026-3888-bug-lets-attackers.html https://t.co/TbHAb81hye

    Post summary

    The post references CVE‑2026‑3888 on Ubuntu 24.04, claiming a 3‑click root exploit, but offers no technical or remediation details.

    19041225.6K
    6.5K followersView on X
  • NullSecurityX@NullSecurityX
    General

    🚨 CVE-2026-3888: Nginx-UI Backup Leak to Root Shell + CVE-2026-27944 Snap Copy-Fail Root We’re going to have a lot of fun with this one 😈 Wait for tomorrow… Don’t forget to follow our YouTube channel: https://www.youtube.com/@NullSecurityX https://t.co/uwGx5EK8ws

    Post summary

    The tweet teases coverage of two CVEs involving root shell exploits with no PoC or exploit tool disclosed, suggesting a future video release but offering no technical or mitigation details.

    19041132.4K
    12.3K followersView on X
  • VulnTracker@vuln_tracker
    General

    @DevuanOrg @DevuanOrg Classic systemd moment with CVE-2026-3888. The snap-confine interaction making this even worse shows how complex the Ubuntu stack has become. Devuan users definitely dodging this particular headache. Deep dive analysis: http://vulntracker.io/blog/ubuntu-snap-cve-2026-3888-privilege-escalation/

    Post summary

    The tweet references CVE‑2026‑3888 and notes complexity in the Ubuntu stack, but provides no PoC, exploit, patch, or detailed vulnerability information.

    0904012.6K
    433 followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    Ubuntu CVE-2026-3888 Bug Lets Attackers Gain Root via systemd Cleanup Timing Exploit https://thehackernews.com/2026/03/ubuntu-cve-2026-3888-bug-lets-attackers.html

    Post summary

    The text announces a new CVE (CVE-2026-3888) that allows attackers to gain root privileges via a systemd cleanup timing flaw, but no PoC, exploit code, patches, or evidence of active exploitation is mentioned.

    111028102.8K
    153.3K followersView on X
  • Open Source Security mailing list@oss_security
    Active Exploitation

    CVE-2026-3888: snap-confine + systemd-tmpfiles = root https://www.openwall.com/lists/oss-security/2026/03/17/8 as discovered by @Qualys Case study: Ubuntu Desktop 24.04 - Analysis - Exploitation Case study: Ubuntu Desktop 25.10 - Overview - Exploitation A quick note on the uutils coreutils (the rust-coreutils)

    Post summary

    The post describes a privilege‑escalation vulnerability (CVE‑2026‑3888) in Ubuntu’s snap‑confine and systemd‑tmpfiles, with evidence of exploitation in Ubuntu Desktop 24.04 and 25.10, but no patch or PoC material is provided.

    2402082.4K
    4.4K followersView on X
  • 0xdf@0xdf_
    Exploit

    Snapped from @hackthebox_eu features CVE-2026-27944 to download and decrypt Nginx UI backups without auth, bcrypt cracking for a shell, and CVE-2026-3888 to exploit a snapd race condition for root. https://0xdf.gitlab.io/2026/04/01/htb-snapped.html

    Post summary

    The post highlights the exploitation of CVE‑2026‑27944 and CVE‑2026‑3888 in a Hack The Box challenge, detailing how to access Nginx backups and achieve root via a snapd race condition.

    0401982.1K
    26.5K followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    Qualys discovers CVE-2026-3888, a critical Local Privilege Escalation (LPE) flaw in Ubuntu Desktop. Learn how a 30-day time window exposes root access. #UbuntuSecurity #CVE #LinuxSecurity #CyberSecurity #InfoSec #LPE #Qualys #Vulnerability #PatchAlert https://securityonline.info/digital-janitor-rogue-30-day-ubuntu-lpe-flaw-cve-2026-3888/ https://t.co/VsIwD3NkRb

    Post summary

    Qualys announced a critical LPE vulnerability (CVE‑2026‑3888) affecting Ubuntu Desktop, highlighting a 30‑day period that could let attackers gain root access. No active exploitation, patch, or PoC details are provided.

    130177829
    10.7K followersView on X
  • elhacker.NET@elhackernet
    Disclosure

    [Blog] CVE-2026-3888 en Ubuntu: escalada a root aprovechando snap-confine y la limpieza de systemd-tmpfiles https://blog.elhacker.net/2026/03/cve-2026-3888-en-ubuntu-escalada-root.html

    Post summary

    The blog announces that CVE-2026-3888 allows Ubuntu users to achieve root escalation by abusing snap‑confine and systemd‑tmpfiles cleanup, detailing how the vulnerability works but showing no sign of active exploitation or patch availability.

    0601821.6K
    138.6K followersView on X
  • Qualys@qualys
    Disclosure

    The Qualys Threat Research Unit (TRU) has identified a Local Privilege Escalation (LPE) vulnerability, CVE-2026-3888, affecting default installations of Ubuntu Desktop v.24.04 and later. This flaw allows a local attacker to escalate privileges to full root access through the interaction of two standard system components. Read the blog for details: https://blog.qualys.com/vulnerabilities-threat-research/2026/03/17/cve-2026-3888-important-snap-flaw-enables-local-privilege-escalation-to-root #ThreatVulnerability #TRU

    Post summary

    Qualys Threat Research Unit discloses CVE-2026-3888, a Local Privilege Escalation flaw in default Ubuntu Desktop 24.04+ that lets local attackers gain root through interaction of two system components; no exploits, patches or PoC are mentioned.

    0401331.2K
    34.2K followersView on X
  • ❄️ winter ❄️@_winter_wonders
    General

    enjoyed @qualys writeup on CVE-2026-3888 but it does kinda suck that there's no attribution to the individuals who found the bug, if ur out there bug-finder individuals, ur cool

    Post summary

    The statement acknowledges a Qualys writeup on CVE‑2026‑3888 but offers no technical details, exploit information, or patch guidance, simply noting lack of attribution.

    210160728
    2.5K followersView on X
  • IT-Connect.fr@ITConnect_fr
    Disclosure

    🛑 Ubuntu - CVE-2026-3888 Quand le nettoyage système d’Ubuntu offre un accès root... Qui est affecté ? Comment se protéger ? Le récap' dans cet article de Florian 👇 - https://www.it-connect.fr/cve-2026-3888-quand-le-nettoyage-systeme-dubuntu-offre-un-acces-root/ #Linux #infosec #ubuntu #cybersecurite https://t.co/g5Nr4b8dz4

    Post summary

    The tweet announces a new Ubuntu vulnerability (CVE‑2026‑3888) that can grant root access during system cleanup, but it offers no technical details, exploits, or patches.

    06063851
    11.0K followersView on X
  • TheCyberGeek@TheCyberGeek19
    PoC

    Dropped a PoC for both variants of CVE-2026-3888. A new box called Snapped showcasing the Ubuntu 24.04 SUID variant has just been released on HackTheBox, check it out here: https://app.hackthebox.com/machines/Snapped Check out my github repo: https://github.com/TheCyberGeek/CVE-2026-3888-snap-confine-systemd-tmpfiles-LPE https://t.co/oY4DkEzXOP

    Post summary

    The author shares a proof‑of‑concept and executable code for CVE‑2026‑3888 variants, along with a HackTheBox machine demonstrating the SUID route on Ubuntu 24.04.

    010112454
    2.2K followersView on X
  • CyberSecurity88@CSec88
    Disclosure

    Silent Ubuntu Vulnerability Lets Attackers Gain Root Access Without Detection A hidden timing flaw in Ubuntu could silently hand over root access. No clicks, no alerts just patience, and full system control. #Ubuntu #cybersecuritynews Full Story 👉 https://cybersecurity88.com/news/ubuntu-cve-2026-3888-timing-flaw-in-systemd-cleanup-enables-root-privilege-escalation/ https://t.co/ueHHPyrCYv

    Post summary

    The headline reports a newly discovered timing‑based root‑privilege escalation flaw in Ubuntu’s systemd cleanup, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    02072336
    516 followersView on X
  • まい@mai_llj
    Patch

    snapdで権限昇格ができてしまうらしい ubuntuユーザ多そうだしみんなアプデしようね https://ubuntu.com/security/CVE-2026-3888

    Post summary

    The tweet informs Ubuntu users of a privilege‑escalation vulnerability (CVE‑2026‑3888) and urges them to apply updates.

    00090202
    881 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OScanonicalubuntu_linux16.04--
OScanonicalubuntu_linux18.04--
OScanonicalubuntu_linux20.04--
OScanonicalubuntu_linux22.04--
OScanonicalubuntu_linux24.04--

Explore more