Ubuntu Snap Flaw Lets Local Users Escalate to Root

Qualys Threat Research Unit disclosed CVE-2026-3888. It affects default Ubuntu Desktop installations 24.04 and later. A 10–30 day cleanup timing window between snap-confine and systemd-tmpfiles allows low-privilege local users to escalate to root, enabling full host compromise; CVSS 7.8.

Part of the PlainSec briefing for 2026-03-18

Sources