CVE-2026-3888: Local Privilege Escalation in snapd
Published Mar 17, 2026
·Updated
Last updated 25 March 2026
Other sources
Local privilege escalation in snapd on Linux allows local attackers to ...
— Debian
Affected Software
7 affected componentsFixes available
Ubuntu Ubuntu>=16.04<24.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=20.04
Canonical Ubuntu Linux=22.04
Canonical Ubuntu Linux=24.04
debian/snapd<=2.49-1+deb11u2, <=2.75.2-2
2.57.6-1+deb12u12.68.3-3+deb13u1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/snapdto a version that resolves this vulnerability.Fixed in 2.57.6-1+deb12u1Fixed in 2.68.3-3+deb13u1
Event History
Mar 17, 2026
CVE Published
via MITRE·02:02 PM
Data Sourced
via MITRE·02:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Mar 18, 2026
Data Sourced
via Launchpad·02:17 PM
Description
Mar 25, 2026
Data Sourced
via Ubuntu·02:23 PM
RemedyDescriptionSeverityAffected Software
Jun 4, 2026
Data Sourced
via Debian·03:48 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-3888?
The severity of CVE-2026-3888 is classified as high due to its potential for local privilege escalation.
2
How do I fix CVE-2026-3888?
To fix CVE-2026-3888, update the snapd package to the latest version that addresses this vulnerability.
3
Who is affected by CVE-2026-3888?
CVE-2026-3888 affects users of Ubuntu 16.04 LTS, 18.04 LTS, and 20.04 LTS.
4
Can CVE-2026-3888 be exploited remotely?
CVE-2026-3888 cannot be exploited remotely as it requires local access to the system.
5
What is the exploit mechanism for CVE-2026-3888?
The exploit mechanism for CVE-2026-3888 involves local attackers re-creating the snap's private /tmp directory.