Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-3888-POC-all-from-the-Qualys-platform. — Proof-of-concept exploit for CVE-2026-3888, a snapd race condition enabling local privilege escalation to root on Ubuntu systems. | Kitploit
Tools/GitHubGitHub/fevar54/cve-2026-3888-poc-all-from-the-qualys-platform.
Privilege EscalationVulnerability AnalysisExploitation
GitHubfevar54/cve-2026-3888-poc-all-from-the-qualys-platform.

CVE-2026-3888-POC-all-from-the-Qualys-platform.

Proof-of-concept exploit for CVE-2026-3888, a snapd race condition enabling local privilege escalation to root on Ubuntu systems.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
216 months agoNot yet reviewed

CVE-2026-3888: snapd Local Privilege Escalation PoC

Proof of concept for the local privilege escalation vulnerability in snapd (CVE-2026-3888). This flaw allows an unprivileged local attacker to elevate their privileges to root on affected Ubuntu systems by recreating the private directory /tmp/.snap after systemd-tmpfiles deletes it.

📋 Vulnerability Summary

  • ID: CVE-2026-3888
  • Product: snapd
  • Affected Systems: Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS (and later)
  • CWE-ID: CWE-268 (Privilege Chaining)
  • Severity (CVSS 3.1): 7.8 (High)
  • Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

The vulnerability arises from an unintended interaction between two privileged utilities:

  1. snap-confine: A setuid-root binary that creates the sandbox environment for snap applications.
  2. systemd-tmpfiles: A service that automatically cleans up old temporary files and directories.

An attacker can exploit this race condition by manipulating the cleanup cycle of systemd-tmpfiles. Once the /tmp/.snap directory is deleted, the attacker recreates it with malicious payloads. During the next sandbox initialization, snap-confine mounts these files as root, allowing arbitrary code execution in the privileged context.

🚨 Impact

  • Full Privilege Escalation: A local attacker can gain full root access on the system.
  • System Compromise: The confidentiality, integrity, and availability of the system are compromised.
  • Affects Default Configurations: The vulnerability is exploitable on default installations of Ubuntu Desktop 24.04 and later.

⚙️ How to Reproduce the Attack

WARNING: This exploit is for educational and authorized security research purposes. Use it at your own risk.

Prerequisites

  • A vulnerable Ubuntu system (see the affected versions section).
  • An unprivileged user.
  • The gcc compiler installed (sudo apt install build-essential).
  • The /tmp/.snap directory must have been deleted by systemd-tmpfiles. This occurs after 30 days on Ubuntu 24.04 or 10 days on later versions. You can simulate the cleanup manually with sudo rm -rf /tmp/.snap.

Exploitation Steps

  1. Clone this repository:

    git clone https://github.com/tu-usuario/cve-2026-3888-poc.git
    cd cve-2026-3888-poc
    
  2. Install the dependencies:

    pip install -r requirements.txt
    
  3. Run the PoC: The script will verify the vulnerability, create the malicious library, and trigger the exploit.

    python3 cve_2026_3888_poc.py
    
  4. Verify the Result: If the exploit succeeds, a file /tmp/pwn.txt will be created with the output of the id command executed as root.

  5. Clean Up the System: To remove the artifacts created by the exploit, run:

    python3 cve_2026_3888_poc.py --cleanup
    

📂 Repository Structure

Download Tool