Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2026-3888
CVE
CVE-2026-3888
View on NVD ↗
Local Privilege Escalation in snapd
MITRE ATT&CK TTPs
3
T1068
Exploitation for Privilege Escalation
Privilege Escalation
T1070.006
Timestomp
Defense Evasion
T1548.001
Setuid and Setgid
Privilege Escalation
Source Articles
Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
A high-severity local privilege escalation vulnerability, CVE-2026-8933, exists in the snap-confine component of default Ubuntu Desktop installations (24.04, 25.10, 26.04), allowing unprivileged users to gain root access. The flaw arises from a race condition during sandbox initialization, enabling attackers to manipulate temporary file ownership and permissions. By exploiting symbolic links and FUSE file systems, an attacker can write malicious rules to sensitive system paths and achieve arbitrary code execution as root.
hacker-news
Jul 22, 2026