
Proof-of-concept exploit for CVE-2026-3888, a snapd race condition enabling local privilege escalation to root on Ubuntu systems.
Proof of concept for the local privilege escalation vulnerability in snapd (CVE-2026-3888). This flaw allows an unprivileged local attacker to elevate their privileges to root on affected Ubuntu systems by recreating the private directory /tmp/.snap after systemd-tmpfiles deletes it.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:HThe vulnerability arises from an unintended interaction between two privileged utilities:
An attacker can exploit this race condition by manipulating the cleanup cycle of systemd-tmpfiles. Once the /tmp/.snap directory is deleted, the attacker recreates it with malicious payloads. During the next sandbox initialization, snap-confine mounts these files as root, allowing arbitrary code execution in the privileged context.
root access on the system.WARNING: This exploit is for educational and authorized security research purposes. Use it at your own risk.
gcc compiler installed (sudo apt install build-essential)./tmp/.snap directory must have been deleted by systemd-tmpfiles. This occurs after 30 days on Ubuntu 24.04 or 10 days on later versions. You can simulate the cleanup manually with sudo rm -rf /tmp/.snap.Clone this repository:
git clone https://github.com/tu-usuario/cve-2026-3888-poc.git
cd cve-2026-3888-poc
Install the dependencies:
pip install -r requirements.txt
Run the PoC: The script will verify the vulnerability, create the malicious library, and trigger the exploit.
python3 cve_2026_3888_poc.py
Verify the Result:
If the exploit succeeds, a file /tmp/pwn.txt will be created with the output of the id command executed as root.
Clean Up the System: To remove the artifacts created by the exploit, run:
python3 cve_2026_3888_poc.py --cleanup