CVE-2026-87798
- EPSS 0.19%
- Veröffentlicht 28.09.2026 13:22:36
- Zuletzt bearbeitet 28.09.2026 17:17:51
Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine to write attacker-c...
CVE-2026-87799
- EPSS 0.41%
- Veröffentlicht 28.09.2026 13:22:29
- Zuletzt bearbeitet 29.09.2026 04:18:01
Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a project, or a m...
CVE-2026-97335
- EPSS 0.21%
- Veröffentlicht 28.09.2026 13:22:19
- Zuletzt bearbeitet 28.09.2026 17:17:53
Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create custom volumes in a project to copy,...
CVE-2026-85185
- EPSS 0.36%
- Veröffentlicht 28.09.2026 13:21:51
- Zuletzt bearbeitet 28.09.2026 17:17:51
Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the ...
CVE-2026-85526
- EPSS 0.52%
- Veröffentlicht 28.09.2026 13:21:40
- Zuletzt bearbeitet 29.09.2026 04:18:00
Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvo...
CVE-2026-86335
- EPSS 0.23%
- Veröffentlicht 28.09.2026 13:21:29
- Zuletzt bearbeitet 28.09.2026 17:17:51
Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance import requests.
CVE-2026-86334
- EPSS 0.34%
- Veröffentlicht 28.09.2026 13:21:15
- Zuletzt bearbeitet 28.09.2026 18:17:25
Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite arbitrary local fil...
CVE-2026-66897
- EPSS 0.62%
- Veröffentlicht 24.08.2026 10:16:39
- Zuletzt bearbeitet 11.09.2026 15:28:53
A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template p...
CVE-2026-16033
- EPSS 0.3%
- Veröffentlicht 12.08.2026 20:11:08
- Zuletzt bearbeitet 11.09.2026 18:23:30
A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the in...
CVE-2026-66898
- EPSS 0.34%
- Veröffentlicht 12.08.2026 20:07:32
- Zuletzt bearbeitet 11.09.2026 15:30:05
A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained with...