Qualys disclosed CVE-2026-3888, a high-severity local privilege escalation flaw affecting default installations of Ubuntu Desktop 24.04 and later. The bug arises from the interaction between snap-confine, the setuid-root component used to build snap sandboxes, and systemd-tmpfiles, which periodically cleans stale data from temporary directories. An unprivileged local attacker can abuse the cleanup of /tmp/.snap, recreate the directory with malicious content, and eventually obtain full root access. The issue is rated CVSS 7.8 and requires low privileges and no user interaction, but exploitation is constrained by a time-based window tied to the system's cleanup schedule.
The vulnerable behavior is present in default Ubuntu Desktop deployments because both components are standard parts of the platform's snap confinement model. Reports note the cleanup interval is typically 30 days on Ubuntu 24.04 and 10 days on later versions, which contributes to the exploit's higher attack complexity. Patched versions include snapd 2.73+ubuntu24.04.1 for Ubuntu 24.04 LTS, 2.73+ubuntu25.10.1 for Ubuntu 25.10 LTS, 2.74.1+ubuntu26.04.1 for Ubuntu 26.04 development builds, and upstream snapd 2.75. A separate report about CVE-2026-32746 in GNU InetUtils telnetd describes a different, unrelated unauthenticated remote code execution issue and does not pertain to the Ubuntu snap-confine flaw.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Qualys Threat Research Unit disclosed CVE-2026-3888, a high-severity local privilege escalation vulnerability caused by an interaction between snap-confine and systemd-tmpfiles. The bug lets an attacker abuse cleanup and recreation of /tmp/.snap so attacker-controlled files may be bind-mounted as root, potentially leading to full system compromise.
Canonical issued patched snapd releases to address CVE-2026-3888 for Ubuntu 24.04 LTS, Ubuntu 25.10, Ubuntu 26.04 LTS (Dev), and upstream snapd. The flaw affects default Ubuntu Desktop 24.04 and later installations and can allow a low-privileged local user to gain full root access.
During review of Ubuntu 25.10, Qualys identified a separate race condition in the uutils coreutils rm utility that could enable arbitrary file deletion as root or further privilege escalation. Ubuntu mitigated the issue before the public release of Ubuntu 25.10 by reverting the default rm command to GNU coreutils, and upstream uutils fixes were later applied.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourceitpro.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.