Search

Find a vulnerability

Search criteria

    578 vulnerabilities

    CVE-2026-102371 (GCVE-0-2026-102371)

    Vulnerability from cvelistv5 – Published: 2026-09-29 14:11 – Updated: 2026-09-30 15:28
    VLAI
    Title
    wsl-pro-service: Ubuntu Pro token exposed via process command-line arguments
    Summary
    In wsl-pro-service before 0.1.19ubuntu3, the service component which runs as root inside each WSL instance attaches the instance to Ubuntu Pro by executing the pro client with the Ubuntu Pro token passed as a command-line argument (pro attach <token>). On systems where /proc is mounted without process-hiding mitigations (such as hidepid), which is the default in WSL, an unprivileged local user or process in the same WSL instance can read the token from /proc/<pid>/cmdline while the attach process is running. The leaked token could then be used to attach other machines to the victim's Ubuntu Pro subscription and gain unauthorized access to Ubuntu Pro services.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 15:17 UTC
    CWE
    • CWE-214 - Invocation of process using visible sensitive information
    Impacted products
    Vendor Product Version
    Canonical Ubuntu Pro for WSL Affected: 0.1.1 , < 0.1.19ubuntu2 (ubuntu-resolute)
    Affected: 0.1.1 , < 0.1.18~24.04.3 (ubuntu-noble)
    Affected: 0.1.1 , < 0.1.18~22.04.2 (ubuntu-jammy)
    Affected: 0.1.1 , < 0.1.18~20.04.2 (ubuntu-focal)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-102371",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T15:17:31.871369Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T15:28:19.783Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "wsl-pro-service",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu Pro for WSL",
              "repo": "https://github.com/canonical/ubuntu-pro-for-wsl",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "0.1.19ubuntu2",
                  "status": "affected",
                  "version": "0.1.1",
                  "versionType": "ubuntu-resolute"
                },
                {
                  "lessThan": "0.1.18~24.04.3",
                  "status": "affected",
                  "version": "0.1.1",
                  "versionType": "ubuntu-noble"
                },
                {
                  "lessThan": "0.1.18~22.04.2",
                  "status": "affected",
                  "version": "0.1.1",
                  "versionType": "ubuntu-jammy"
                },
                {
                  "lessThan": "0.1.18~20.04.2",
                  "status": "affected",
                  "version": "0.1.1",
                  "versionType": "ubuntu-focal"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Darshan U"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Carlos Nihelton"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In wsl-pro-service before 0.1.19ubuntu3, the service component which runs as root inside each WSL instance attaches the instance to Ubuntu Pro by executing the pro client with the Ubuntu Pro token passed as a command-line argument (pro attach \u003ctoken\u003e). On systems where /proc is mounted without process-hiding mitigations (such as hidepid), which is the default in WSL, an unprivileged local user or process in the same WSL instance can read the token from /proc/\u003cpid\u003e/cmdline while the attach process is running. The leaked token could then be used to attach other machines to the victim\u0027s Ubuntu Pro subscription and gain unauthorized access to Ubuntu Pro services."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-639",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-639 Probe System Files"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "LOCAL",
                "baseScore": 5.7,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-214",
                  "description": "CWE-214 Invocation of process using visible sensitive information",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T14:11:19.350Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/ubuntu-pro-for-wsl/pull/1816"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/ubuntu-pro-for-wsl/commit/11c164a37b806bcf2a2304beb0d65e406739778b"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://ubuntu.com/security/CVE-2026-102371"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "wsl-pro-service: Ubuntu Pro token exposed via process command-line arguments",
          "x_generator": {
            "engine": "cvelib 1.8.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-102371",
        "datePublished": "2026-09-29T14:11:19.350Z",
        "dateReserved": "2026-09-28T23:44:11.787Z",
        "dateUpdated": "2026-09-30T15:28:19.783Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-42002 (GCVE-0-2024-42002)

    Vulnerability from cvelistv5 – Published: 2026-09-28 21:38 – Updated: 2026-09-30 13:43
    VLAI
    Title
    Unsafe use of eval() method in ros2 topic hz tool
    Summary
    A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distributions from Crystal Clemmys up to and including Lyrical Luth and Rolling Ridley. The vulnerability lies in the 'hz' verb, which reports the publishing rate of a topic and accepts a user-provided Python expression via the --filter option. This input is passed directly to the eval() function without sanitization, allowing a local user to craft and execute arbitrary code.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 13:43 UTC
    CWE
    • CWE-95 - Improper neutralization of directives in dynamically evaluated code ('eval injection')
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    Impacted products
    Vendor Product Version
    Open Source Robotics Foundation Robot Operating System 2 (ROS 2) Affected: Rolling Ridley (custom)
    Affected: Lyrical Luth (custom)
    Affected: Kilted Kaiju (custom)
    Affected: Jazzy Jalisco (custom)
    Affected: Iron Irwini (custom)
    Affected: Humble Hawksbill (custom)
    Affected: Galactic Geochelone (custom)
    Affected: Foxy Fitzroy (custom)
    Affected: Eloquent Elusor (custom)
    Affected: Dashing Diademata (custom)
    Affected: Crystal Clemmys (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-42002",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T13:43:08.696167Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T13:43:15.912Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "ros2topic"
              ],
              "packageName": "ros2topic",
              "platforms": [
                "Linux",
                "MacOS",
                "Windows"
              ],
              "product": "Robot Operating System 2 (ROS 2)",
              "programFiles": [
                "ros2topic/ros2topic/verb/hz.py"
              ],
              "repo": "https://github.com/ros2/ros2cli",
              "vendor": "Open Source Robotics Foundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Rolling Ridley",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "Lyrical Luth",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "Kilted Kaiju",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "Jazzy Jalisco",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "Iron Irwini",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "Humble Hawksbill",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "Galactic Geochelone",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "Foxy Fitzroy",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "Eloquent Elusor",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "Dashing Diademata",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "Crystal Clemmys",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Florencia Cabral Berenfus, Ubuntu Robotics Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) \u0027ros2topic\u0027 command-line tool, affecting all ROS 2 distributions from Crystal Clemmys up to and including Lyrical Luth and Rolling Ridley. The vulnerability lies in the \u0027hz\u0027 verb, which reports the publishing rate of a topic and accepts a user-provided Python expression via the --filter option. This input is passed directly to the eval() function without sanitization, allowing a local user to craft and execute arbitrary code."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-242",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-242 Code Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 8.4,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-95",
                  "description": "CWE-95 Improper neutralization of directives in dynamically evaluated code (\u0027eval injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-94",
                  "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T21:38:08.369Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/ros2/ros2cli/pull/1001"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/ros2/ros2cli/pull/133#discussion_r223081766"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "No fixed release is available at the time of publication. A fix is proposed upstream in https://github.com/ros2/ros2cli/pull/1001."
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "Unsafe use of eval() method in ros2 topic hz tool",
          "workarounds": [
            {
              "lang": "en",
              "value": "Do not pass untrusted or unreviewed input to the --filter option of \u0027ros2 topic hz\u0027."
            }
          ],
          "x_generator": {
            "engine": "cvelib 1.8.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2024-42002",
        "datePublished": "2026-09-28T21:38:08.369Z",
        "dateReserved": "2024-08-01T12:00:12.183Z",
        "dateUpdated": "2026-09-30T13:43:15.912Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-87798 (GCVE-0-2026-87798)

    Vulnerability from cvelistv5 – Published: 2026-09-28 13:22 – Updated: 2026-09-28 16:32
    VLAI
    Title
    LXD client recursive file pull allows directory escape via malicious VM agent
    Summary
    Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine to write attacker-controlled files or directory trees to arbitrary paths on the client host, with the operator's privileges. The attacker does this by using a modified lxd-agent that returns inconsistent SFTP directory listings and Lstat results.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 14:04 UTC
    CWE
    • CWE-59 - Improper link resolution before file access ('link following')
    References
    Impacted products
    Vendor Product Version
    Canonical LXD Affected: 4.0.2 , < 4.0.14 (semver)
    Affected: 5.0.0 , < 5.0.10 (semver)
    Affected: 5.21.0 , < 5.21.8 (semver)
    Affected: 6.0 , < 6.9 (semver)
    Create a notification for this product.
    Date Public
    2026-09-25 03:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-87798",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T14:04:47.395647Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T16:32:28.148Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "LXD",
              "platforms": [
                "Linux"
              ],
              "product": "LXD",
              "repo": "https://github.com/canonical/lxd",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "4.0.14",
                  "status": "affected",
                  "version": "4.0.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.0.10",
                  "status": "affected",
                  "version": "5.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.21.8",
                  "status": "affected",
                  "version": "5.21.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.9",
                  "status": "affected",
                  "version": "6.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "datePublic": "2026-09-25T03:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine to write attacker-controlled files or directory trees to arbitrary paths on the client host, with the operator\u0027s privileges. The attacker does this by using a modified lxd-agent that returns inconsistent SFTP directory listings and Lstat results."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-132",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-132 Symlink Attack"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.8,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-59",
                  "description": "CWE-59 Improper link resolution before file access (\u0027link following\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T13:22:36.561Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/canonical/lxd/security/advisories/GHSA-mr8v-hx34-hfvf"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8 or later."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "LXD client recursive file pull allows directory escape via malicious VM agent"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-87798",
        "datePublished": "2026-09-28T13:22:36.561Z",
        "dateReserved": "2026-09-09T10:00:46.383Z",
        "dateUpdated": "2026-09-28T16:32:28.148Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-87799 (GCVE-0-2026-87799)

    Vulnerability from cvelistv5 – Published: 2026-09-28 13:22 – Updated: 2026-09-29 03:55
    VLAI
    Title
    Arbitrary file write on LXD host via symlink in migration stream
    Summary
    Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a project, or a malicious migration source server, to write attacker-controlled files to arbitrary paths on the target host as root, leading to full host compromise. The attacker does this with a crafted rsync or btrfs send stream that plants a symlink in the transferred volume, such as rootfs or root.img, and then writes through it.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 00:00 UTC
    CWE
    • CWE-59 - Improper link resolution before file access ('link following')
    References
    Impacted products
    Vendor Product Version
    Canonical LXD Affected: 4.0.0 , < 4.0.14 (semver)
    Affected: 5.0.0 , < 5.0.10 (semver)
    Affected: 5.21.0 , < 5.21.8 (semver)
    Affected: 6.0 , < 6.10 (semver)
    Create a notification for this product.
    Date Public
    2026-09-25 03:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-87799",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T03:55:19.115Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "LXD",
              "platforms": [
                "Linux"
              ],
              "product": "LXD",
              "repo": "https://github.com/canonical/lxd",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "4.0.14",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.0.10",
                  "status": "affected",
                  "version": "5.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.21.8",
                  "status": "affected",
                  "version": "5.21.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.10",
                  "status": "affected",
                  "version": "6.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "datePublic": "2026-09-25T03:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a project, or a malicious migration source server, to write attacker-controlled files to arbitrary paths on the target host as root, leading to full host compromise. The attacker does this with a crafted rsync or btrfs send stream that plants a symlink in the transferred volume, such as rootfs or root.img, and then writes through it."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-132",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-132 Symlink Attack"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-59",
                  "description": "CWE-59 Improper link resolution before file access (\u0027link following\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T13:22:29.148Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/canonical/lxd/security/advisories/GHSA-fmc3-3cpq-6whr"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8, 6.10 or later."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Arbitrary file write on LXD host via symlink in migration stream"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-87799",
        "datePublished": "2026-09-28T13:22:29.148Z",
        "dateReserved": "2026-09-09T10:00:46.383Z",
        "dateUpdated": "2026-09-29T03:55:19.115Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-97335 (GCVE-0-2026-97335)

    Vulnerability from cvelistv5 – Published: 2026-09-28 13:22 – Updated: 2026-09-28 16:32
    VLAI
    Title
    Incorrect authorization in LXD storage volume API allows reading volumes from other projects
    Summary
    Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create custom volumes in a project to copy, and so read, any custom storage volume from any other project on the server, including its snapshots and configuration. The client does this with a crafted request that sets a source volume and source.project but omits source.type.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 14:02 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    References
    Impacted products
    Vendor Product Version
    Canonical LXD Affected: 5.0.0 , < 5.0.10 (semver)
    Affected: 5.21.0 , < 5.21.8 (semver)
    Affected: 6.0 , < 6.10 (semver)
    Create a notification for this product.
    Date Public
    2026-09-25 03:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-97335",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T14:02:18.270198Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T16:32:28.403Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "LXD",
              "platforms": [
                "Linux"
              ],
              "product": "LXD",
              "repo": "https://github.com/canonical/lxd",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "5.0.10",
                  "status": "affected",
                  "version": "5.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.21.8",
                  "status": "affected",
                  "version": "5.21.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.10",
                  "status": "affected",
                  "version": "6.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "datePublic": "2026-09-25T03:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create custom volumes in a project to copy, and so read, any custom storage volume from any other project on the server, including its snapshots and configuration. The client does this with a crafted request that sets a source volume and source.project but omits source.type."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-122",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-122 Privilege Abuse"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "CWE-863 Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T13:22:19.371Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/canonical/lxd/security/advisories/GHSA-p456-92fx-44xh"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to LXD versions 5.0.10, 5.21.8, 6.10 or later."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Incorrect authorization in LXD storage volume API allows reading volumes from other projects"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-97335",
        "datePublished": "2026-09-28T13:22:19.371Z",
        "dateReserved": "2026-09-24T12:15:00.374Z",
        "dateUpdated": "2026-09-28T16:32:28.403Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-85185 (GCVE-0-2026-85185)

    Vulnerability from cvelistv5 – Published: 2026-09-28 13:21 – Updated: 2026-09-28 16:32
    VLAI
    Title
    Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root
    Summary
    Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is btrfs, the client can also place attacker-controlled content at arbitrary host paths, leading to full host compromise. The client does this with a crafted subvolume path containing ../ sequences, sent in either of two ways: in the optimized_header.yaml of an optimized btrfs backup, or in the btrfs migration header sent by a malicious migration source.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 13:55 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    References
    Impacted products
    Vendor Product Version
    Canonical LXD Affected: 4.0.2 , < 4.0.14 (semver)
    Affected: 5.0.0 , < 5.0.10 (semver)
    Affected: 5.21.0 , < 5.21.8 (semver)
    Affected: 6.0 , < 6.10 (semver)
    Create a notification for this product.
    Date Public
    2026-09-25 03:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-85185",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T13:55:28.506443Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T16:32:28.529Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "LXD",
              "platforms": [
                "Linux"
              ],
              "product": "LXD",
              "repo": "https://github.com/canonical/lxd",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "4.0.14",
                  "status": "affected",
                  "version": "4.0.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.0.10",
                  "status": "affected",
                  "version": "5.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.21.8",
                  "status": "affected",
                  "version": "5.21.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.10",
                  "status": "affected",
                  "version": "6.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "datePublic": "2026-09-25T03:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is btrfs, the client can also place attacker-controlled content at arbitrary host paths, leading to full host compromise. The client does this with a crafted subvolume path containing ../ sequences, sent in either of two ways: in the optimized_header.yaml of an optimized btrfs backup, or in the btrfs migration header sent by a malicious migration source."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-126",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-126 Path Traversal"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.6,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T13:21:51.596Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/canonical/lxd/security/advisories/GHSA-27q7-qwhm-c34p"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8, 6.10 or later."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-85185",
        "datePublished": "2026-09-28T13:21:51.596Z",
        "dateReserved": "2026-09-03T11:46:34.569Z",
        "dateUpdated": "2026-09-28T16:32:28.529Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-85526 (GCVE-0-2026-85526)

    Vulnerability from cvelistv5 – Published: 2026-09-28 13:21 – Updated: 2026-09-29 03:55
    VLAI
    Title
    Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD
    Summary
    Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvolumes[].path entry in backup/optimized_header.yaml during a btrfs optimized backup import.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 00:00 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    Canonical LXD Affected: 4.0.0 , < 4.0.14 (semver)
    Affected: 5.0.0 , < 5.0.10 (semver)
    Affected: 5.21.0 , < 5.21.8 (semver)
    Affected: 6.0 , < 6.10 (semver)
    Create a notification for this product.
    Date Public
    2026-09-25 03:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-85526",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T03:55:18.376Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "LXD",
              "platforms": [
                "Linux"
              ],
              "product": "LXD",
              "repo": "https://github.com/canonical/lxd",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "4.0.14",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.0.10",
                  "status": "affected",
                  "version": "5.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.21.8",
                  "status": "affected",
                  "version": "5.21.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.10",
                  "status": "affected",
                  "version": "6.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "datePublic": "2026-09-25T03:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvolumes[].path entry in backup/optimized_header.yaml during a btrfs optimized backup import."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-126",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-126 Path Traversal"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T13:21:40.621Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "issue-tracking"
              ],
              "url": "https://github.com/canonical/lxd/security/advisories/GHSA-h85r-gjgx-g2rv"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/lxd-private/pull/87"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/lxd-private/pull/105"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/lxd-private/pull/104"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/lxd-private/pull/103"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/lxd-private/pull/84"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8, 6.10 or later."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-85526",
        "datePublished": "2026-09-28T13:21:40.621Z",
        "dateReserved": "2026-09-04T08:34:29.842Z",
        "dateUpdated": "2026-09-29T03:55:18.376Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-86335 (GCVE-0-2026-86335)

    Vulnerability from cvelistv5 – Published: 2026-09-28 13:21 – Updated: 2026-09-28 16:32
    VLAI
    Title
    LXD Cross-Project Private Image Theft via Unsanitized GetImageFromAnyProject Local Reuse
    Summary
    Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance import requests.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 13:49 UTC
    CWE
    Impacted products
    Vendor Product Version
    Canonical LXD Affected: 5.21.0 , < 5.21.8 (semver)
    Affected: 6.0 , < 6.10 (semver)
    Affected: 4.0 , < 5.0.10 (semver)
    Create a notification for this product.
    Date Public
    2026-09-25 03:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-86335",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T13:49:04.323716Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T16:32:28.655Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "LXD",
              "product": "LXD",
              "repo": "https://github.com/canonical/lxd",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "5.21.8",
                  "status": "affected",
                  "version": "5.21.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.10",
                  "status": "affected",
                  "version": "6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.0.10",
                  "status": "affected",
                  "version": "4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Yuliang Xiao"
            }
          ],
          "datePublic": "2026-09-25T03:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Missing Authorization in imageDownload in Canonical LXD before 5.0.10,\u00a05.21.8, and 6.10\u00a0on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance import requests."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-122",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-122 Privilege Abuse"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T13:21:29.891Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "issue-tracking"
              ],
              "url": "https://github.com/canonical/lxd/security/advisories/GHSA-j7p3-5g2v-69j8"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/lxd/pull/19003"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/lxd/pull/19002"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/lxd/pull/19001"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/lxd/pull/18987"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to LXD versions 5.0.10, 5.21.8, 6.10 or later."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "LXD Cross-Project Private Image Theft via Unsanitized GetImageFromAnyProject Local Reuse"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-86335",
        "datePublished": "2026-09-28T13:21:29.891Z",
        "dateReserved": "2026-09-07T08:01:22.942Z",
        "dateUpdated": "2026-09-28T16:32:28.655Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-86334 (GCVE-0-2026-86334)

    Vulnerability from cvelistv5 – Published: 2026-09-28 13:21 – Updated: 2026-09-28 17:56
    VLAI
    Title
    CLI Path Traversal via Content-Disposition in LXD Image Export/Copy
    Summary
    Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite arbitrary local files and execute code on the client system via a crafted Content-Disposition header filename parameter during unified image export or copy operations into a local directory target.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 17:55 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    Canonical LXD Affected: 4.0.2 , < 4.0.14 (semver)
    Affected: 5.0.0 , < 5.0.10 (semver)
    Affected: 5.21.0 , < 5.21.8 (semver)
    Affected: 6.0 , < 6.10 (semver)
    Create a notification for this product.
    Date Public
    2026-09-25 03:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-86334",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T17:55:41.286474Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T17:56:11.126Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/canonical/lxd/security/advisories/GHSA-g4cm-f533-78hq"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "LXD",
              "platforms": [
                "Linux"
              ],
              "product": "LXD",
              "repo": "https://github.com/canonical/lxd",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "4.0.14",
                  "status": "affected",
                  "version": "4.0.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.0.10",
                  "status": "affected",
                  "version": "5.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.21.8",
                  "status": "affected",
                  "version": "5.21.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.10",
                  "status": "affected",
                  "version": "6.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "datePublic": "2026-09-25T03:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite arbitrary local files and execute code on the client system via a crafted Content-Disposition header filename parameter during unified image export or copy operations into a local directory target."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-126",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-126 Path Traversal"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 4.2,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T13:21:15.612Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "issue-tracking"
              ],
              "url": "https://github.com/canonical/lxd/security/advisories/GHSA-g4cm-f533-78hq"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/lxd/pull/18977"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/lxd/pull/18976"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/lxd/pull/18974"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/lxd/pull/18975"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/lxd/pull/18940"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8, 6.10 or later."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CLI Path Traversal via Content-Disposition in LXD Image Export/Copy"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-86334",
        "datePublished": "2026-09-28T13:21:15.612Z",
        "dateReserved": "2026-09-07T08:01:22.941Z",
        "dateUpdated": "2026-09-28T17:56:11.126Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-79619 (GCVE-0-2026-79619)

    Vulnerability from cvelistv5 – Published: 2026-08-26 12:50 – Updated: 2026-08-27 17:32
    VLAI
    Title
    OpenZFS: user-namespace capability check allows unprivileged local authorization bypass
    Summary
    On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that should require root. Affected operations include pool-administrative operations (eg create, import, destroy), pool event log access (zpool events) and fault injection (zinject). Exploiting the problem requires only that the local user is permitted to open /dev/zfs (governed by local device permissions) and that the kernel permits unprivileged user namespace creation. No prior access to the target pool or its underlying devices is needed.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-26 15:47 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    OpenZFS OpenZFS Affected: 0.7.0 , < 2.2.11 (semver)
    Affected: 2.3.0 , < 2.3.9 (semver)
    Affected: 2.4.0 , < 2.4.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-79619",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-26T15:47:13.454769Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-26T15:47:19.764Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Linux"
              ],
              "product": "OpenZFS",
              "repo": "https://github.com/openzfs/zfs",
              "vendor": "OpenZFS",
              "versions": [
                {
                  "lessThan": "2.2.11",
                  "status": "affected",
                  "version": "0.7.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.3.9",
                  "status": "affected",
                  "version": "2.3.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.4.4",
                  "status": "affected",
                  "version": "2.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Erica Windisch"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Rob Norris"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that should require root. Affected operations include pool-administrative operations (eg create, import, destroy), pool event log access (zpool events) and fault injection (zinject). Exploiting the problem requires only that the local user is permitted to open /dev/zfs (governed by local device permissions) and that the kernel permits unprivileged user namespace creation. No prior access to the target pool or its underlying devices is needed."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "LOCAL",
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "CWE-863 Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-27T17:32:03.057Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openzfs/zfs/pull/18959"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/advisories/GHSA-mhf5-q8gw-qg9v"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/openzfs/zfs/releases/tag/zfs-2.4.4"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/openzfs/zfs/releases/tag/zfs-2.3.9"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/openzfs/zfs/releases/tag/zfs-2.2.11"
            },
            {
              "tags": [
                "mailing-list"
              ],
              "url": "https://seclists.org/fulldisclosure/2026/Aug/40"
            }
          ],
          "title": "OpenZFS: user-namespace capability check allows unprivileged local authorization bypass",
          "x_generator": {
            "engine": "cvelib 1.8.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-79619",
        "datePublished": "2026-08-26T12:50:10.502Z",
        "dateReserved": "2026-08-25T08:10:52.983Z",
        "dateUpdated": "2026-08-27T17:32:03.057Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-66897 (GCVE-0-2026-66897)

    Vulnerability from cvelistv5 – Published: 2026-08-24 09:08 – Updated: 2026-08-25 03:55
    VLAI
    Title
    Instance template path traversal allows arbitrary host file write as root
    Summary
    A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in metadata.yaml, LXD validates the path against a confined os.Root directory handle but subsequently opens and creates the file using os.Create with an unconfined string path. This discrepancy between path resolution checks and file creation allows an attacker to escape directory confinement, overwrite root-owned host files, and achieve host root code execution.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-24 00:00 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    • CWE-23 - Relative Path Traversal
    References
    URL Tags
    https://github.com/canonical/lxd/security/advisor… vdb-entryvendor-advisory
    Impacted products
    Vendor Product Version
    Canonical LXD Affected: 4.0.0 , < 4.0.13 (semver)
    Affected: 5.0.0 , < 5.0.9 (semver)
    Affected: 5.21.0 , < 5.21.7 (semver)
    Affected: 6.0 , < 6.10 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-66897",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-24T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-25T03:55:49.930Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "LXD",
              "platforms": [
                "Linux"
              ],
              "product": "LXD",
              "repo": "https://github.com/canonical/lxd",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "4.0.13",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.0.9",
                  "status": "affected",
                  "version": "5.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.21.7",
                  "status": "affected",
                  "version": "5.21.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.10",
                  "status": "affected",
                  "version": "6.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A path traversal vulnerability in LXD\u0027s instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in metadata.yaml, LXD validates the path against a confined os.Root directory handle but subsequently opens and creates the file using os.Create with an unconfined string path. This discrepancy between path resolution checks and file creation allows an attacker to escape directory confinement, overwrite root-owned host files, and achieve host root code execution."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-126",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Path Traversal"
                }
              ]
            },
            {
              "capecId": "CAPEC-153",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Input Data Manipulation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                },
                {
                  "cweId": "CWE-23",
                  "description": "CWE-23: Relative Path Traversal",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-24T09:08:04.188Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "vdb-entry",
                "vendor-advisory"
              ],
              "url": "https://github.com/canonical/lxd/security/advisories/GHSA-q39m-8fx9-42fv"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to LXD versions 4.0.13, 5.0.9, 5.21.7, 6.10 or later."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Instance template path traversal allows arbitrary host file write as root"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-66897",
        "datePublished": "2026-08-24T09:08:04.188Z",
        "dateReserved": "2026-07-28T07:41:26.310Z",
        "dateUpdated": "2026-08-25T03:55:49.930Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77113 (GCVE-0-2026-77113)

    Vulnerability from cvelistv5 – Published: 2026-08-20 22:32 – Updated: 2026-08-21 20:08
    VLAI
    Title
    Path Traversal Vulnerability in apport-unpack
    Summary
    Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in crash report files.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-21 19:50 UTC
    CWE
    • CWE-23 - Relative path traversal
    References
    Impacted products
    Vendor Product Version
    Canonical Apport Affected: 0 , < 2.36.0 (semver)
    Affected: 0 , < 2.34.2 (semver)
    Affected: 0 , < 2.28.4 (semver)
        cpe:2.3:a:canonical:apport:*:*:linux:*:*:*:*:*
        cpe:2.3:a:canonical:apport:*:*:linux:*:*:*:*:*
        cpe:2.3:a:canonical:apport:*:*:linux:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77113",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-21T19:50:19.847915Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-21T20:08:37.866Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "apport-unpack",
              "platforms": [
                "Linux"
              ],
              "product": "Apport",
              "programFiles": [
                "problem_report.py"
              ],
              "repo": "https://github.com/canonical/apport",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "2.36.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.34.2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.28.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:canonical:apport:*:*:linux:*:*:*:*:*",
                      "versionEndExcluding": "2.36.0",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:canonical:apport:*:*:linux:*:*:*:*:*",
                      "versionEndExcluding": "2.34.2",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:canonical:apport:*:*:linux:*:*:*:*:*",
                      "versionEndExcluding": "2.28.4",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Sakib Sarkar (0xROI)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Path traversal in apport-unpack in Canonical Apport before\u00a02.36.0,\u00a02.34.2, and\u00a02.28.4\u00a0on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in crash report files."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-126",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-126 Path Traversal"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 6.7,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "ACTIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-23",
                  "description": "CWE-23 Relative path traversal",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-20T22:32:51.447Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "issue-tracking",
                "vendor-advisory"
              ],
              "url": "https://launchpad.net/bugs/2161697"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/apport/pull/646"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Path Traversal Vulnerability in apport-unpack",
          "x_generator": {
            "engine": "cvelib 1.8.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-77113",
        "datePublished": "2026-08-20T22:32:51.447Z",
        "dateReserved": "2026-08-20T11:53:23.292Z",
        "dateUpdated": "2026-08-21T20:08:37.866Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-61898 (GCVE-0-2026-61898)

    Vulnerability from cvelistv5 – Published: 2026-08-20 14:32 – Updated: 2026-08-26 19:50
    VLAI
    Title
    accountsservice: shell injection via attacker-controlled ~/.pam_environment in Ubuntu language helper scripts
    Summary
    The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject a sed 'e' flag and arbitrary shell commands that execute with the privileges of the AccountsService helper process (real UID 0) via the SetLanguage D-Bus method.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-26 19:43 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    Impacted products
    Vendor Product Version
    Canonical accountsservice Affected: 22.07.5-2ubuntu1 , < 22.07.5-2ubuntu1.6 (dpkg)
    Affected: 23.13.9-2ubuntu6 , < 23.13.9-2ubuntu6.1 (dpkg)
    Affected: 23.13.9-8ubuntu5 , < 23.13.9-8ubuntu5.2 (dpkg)
    Affected: 23.13.9-8ubuntu6 , < 23.13.9-8ubuntu7 (dpkg)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-61898",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-26T19:43:44.504304Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-26T19:50:34.552Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "accountsservice",
              "platforms": [
                "Ubuntu 14.04 LTS",
                "Ubuntu 16.04 LTS",
                "Ubuntu 18.04 LTS",
                "Ubuntu 20.04 LTS",
                "Ubuntu 22.04 LTS",
                "Ubuntu 24.04 LTS",
                "Ubuntu 26.04 LTS",
                "Ubuntu 26.10"
              ],
              "product": "accountsservice",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "22.07.5-2ubuntu1.6",
                  "status": "affected",
                  "version": "22.07.5-2ubuntu1",
                  "versionType": "dpkg"
                },
                {
                  "lessThan": "23.13.9-2ubuntu6.1",
                  "status": "affected",
                  "version": "23.13.9-2ubuntu6",
                  "versionType": "dpkg"
                },
                {
                  "lessThan": "23.13.9-8ubuntu5.2",
                  "status": "affected",
                  "version": "23.13.9-8ubuntu5",
                  "versionType": "dpkg"
                },
                {
                  "lessThan": "23.13.9-8ubuntu7",
                  "status": "affected",
                  "version": "23.13.9-8ubuntu6",
                  "versionType": "dpkg"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Deutsche Telekom Security GmbH Red Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject a sed \u0027e\u0027 flag and arbitrary shell commands that execute with the privileges of the AccountsService helper process (real UID 0) via the SetLanguage D-Bus method."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-20T14:32:59.924Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "name": "Launchpad Bug #2157985",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://bugs.launchpad.net/ubuntu/+source/accountsservice/+bug/2157985"
            },
            {
              "name": "Ubuntu CVE Tracker",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://ubuntu.com/security/CVE-2026-61898"
            }
          ],
          "title": "accountsservice: shell injection via attacker-controlled ~/.pam_environment in Ubuntu language helper scripts"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-61898",
        "datePublished": "2026-08-20T14:32:59.924Z",
        "dateReserved": "2026-07-11T18:43:51.251Z",
        "dateUpdated": "2026-08-26T19:50:34.552Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-61897 (GCVE-0-2026-61897)

    Vulnerability from cvelistv5 – Published: 2026-08-20 14:32 – Updated: 2026-08-26 19:50
    VLAI
    Title
    accountsservice: incomplete privilege drop when running Ubuntu-specific language helper scripts
    Summary
    An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to root, enabling local privilege escalation.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-26 19:43 UTC
    CWE
    • CWE-273 - Improper Check for Dropped Privileges
    References
    Impacted products
    Vendor Product Version
    Canonical accountsservice Affected: 22.07.5-2ubuntu1 , < 22.07.5-2ubuntu1.6 (dpkg)
    Affected: 23.13.9-2ubuntu6 , < 23.13.9-2ubuntu6.1 (dpkg)
    Affected: 23.13.9-8ubuntu5 , < 23.13.9-8ubuntu5.2 (dpkg)
    Affected: 23.13.9-8ubuntu6 , < 23.13.9-8ubuntu7 (dpkg)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-61897",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-26T19:43:37.600246Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-26T19:50:49.398Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "accountsservice",
              "platforms": [
                "Ubuntu 14.04 LTS",
                "Ubuntu 16.04 LTS",
                "Ubuntu 18.04 LTS",
                "Ubuntu 20.04 LTS",
                "Ubuntu 22.04 LTS",
                "Ubuntu 24.04 LTS",
                "Ubuntu 26.04 LTS",
                "Ubuntu 26.10"
              ],
              "product": "accountsservice",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "22.07.5-2ubuntu1.6",
                  "status": "affected",
                  "version": "22.07.5-2ubuntu1",
                  "versionType": "dpkg"
                },
                {
                  "lessThan": "23.13.9-2ubuntu6.1",
                  "status": "affected",
                  "version": "23.13.9-2ubuntu6",
                  "versionType": "dpkg"
                },
                {
                  "lessThan": "23.13.9-8ubuntu5.2",
                  "status": "affected",
                  "version": "23.13.9-8ubuntu5",
                  "versionType": "dpkg"
                },
                {
                  "lessThan": "23.13.9-8ubuntu7",
                  "status": "affected",
                  "version": "23.13.9-8ubuntu6",
                  "versionType": "dpkg"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Deutsche Telekom Security GmbH Red Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to root, enabling local privilege escalation."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-273",
                  "description": "CWE-273: Improper Check for Dropped Privileges",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-20T14:32:53.827Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "name": "Launchpad Bug #2157985",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://bugs.launchpad.net/ubuntu/+source/accountsservice/+bug/2157985"
            },
            {
              "name": "Ubuntu CVE Tracker",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://ubuntu.com/security/CVE-2026-61897"
            }
          ],
          "title": "accountsservice: incomplete privilege drop when running Ubuntu-specific language helper scripts"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-61897",
        "datePublished": "2026-08-20T14:32:53.827Z",
        "dateReserved": "2026-07-11T18:43:51.251Z",
        "dateUpdated": "2026-08-26T19:50:49.398Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-16033 (GCVE-0-2026-16033)

    Vulnerability from cvelistv5 – Published: 2026-08-12 20:11 – Updated: 2026-08-13 12:46
    VLAI
    Title
    Arbitrary file read+write on host via templates/ symlink in malicious image
    Summary
    A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the instance templates directory (specifically affecting virtual machine / QEMU driver execution paths). An attacker can exploit this flaw by providing a crafted image archive with malicious template directives containing path traversal sequences, causing LXD to access or write files outside the intended template directory on the host system.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-13 12:45 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    References
    URL Tags
    https://github.com/canonical/lxd/security/advisor… vdb-entryvendor-advisory
    Impacted products
    Vendor Product Version
    Canonical LXD Affected: 4.0.0 , < 4.0.12 (semver)
    Affected: 5.0.0 , < 5.0.8 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-16033",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-13T12:45:51.004847Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-13T12:46:08.117Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/canonical/lxd/security/advisories/GHSA-9hcm-hxh5-7xxh"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "LXD",
              "platforms": [
                "Linux"
              ],
              "product": "LXD",
              "repo": "https://github.com/canonical/lxd",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "4.0.12",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.0.8",
                  "status": "affected",
                  "version": "5.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the instance templates directory (specifically affecting virtual machine / QEMU driver execution paths). An attacker can exploit this flaw by providing a crafted image archive with malicious template directives containing path traversal sequences, causing LXD to access or write files outside the intended template directory on the host system."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-126",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Path Traversal"
                }
              ]
            },
            {
              "capecId": "CAPEC-153",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Input Data Manipulation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-12T20:11:08.781Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "vdb-entry",
                "vendor-advisory"
              ],
              "url": "https://github.com/canonical/lxd/security/advisories/GHSA-9hcm-hxh5-7xxh"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to LXD version 4.0.12 or later, or 5.0.8 or later."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Arbitrary file read+write on host via templates/ symlink in malicious image"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-16033",
        "datePublished": "2026-08-12T20:11:08.781Z",
        "dateReserved": "2026-07-17T08:44:31.450Z",
        "dateUpdated": "2026-08-13T12:46:08.117Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-66898 (GCVE-0-2026-66898)

    Vulnerability from cvelistv5 – Published: 2026-08-12 20:07 – Updated: 2026-08-13 13:40
    VLAI
    Title
    Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE
    Summary
    A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside the designated restore directory.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-13 13:40 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    References
    URL Tags
    https://github.com/canonical/lxd/security/advisor… vdb-entryvendor-advisory
    Impacted products
    Vendor Product Version
    Canonical LXD Affected: 4.0.0 , < 4.0.12 (semver)
    Affected: 5.0.0 , < 5.0.4 (semver)
    Affected: 5.21.0 , < 5.21.2 (semver)
    Affected: 6.0 , < 6.1 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-66898",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-13T13:40:15.405663Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-13T13:40:18.070Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/canonical/lxd/security/advisories/GHSA-m857-c7gc-c984"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "LXD",
              "platforms": [
                "Linux"
              ],
              "product": "LXD",
              "repo": "https://github.com/canonical/lxd",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "4.0.12",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.0.4",
                  "status": "affected",
                  "version": "5.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.21.2",
                  "status": "affected",
                  "version": "5.21.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.1",
                  "status": "affected",
                  "version": "6.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside the designated restore directory."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-126",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Path Traversal"
                }
              ]
            },
            {
              "capecId": "CAPEC-153",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Input Data Manipulation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-12T20:07:32.889Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "vdb-entry",
                "vendor-advisory"
              ],
              "url": "https://github.com/canonical/lxd/security/advisories/GHSA-m857-c7gc-c984"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to LXD version 4.0.12 or later, 5.0.4 or later, or 5.12.2 or later, or 6.0 or later."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-66898",
        "datePublished": "2026-08-12T20:07:32.889Z",
        "dateReserved": "2026-07-28T07:41:26.311Z",
        "dateUpdated": "2026-08-13T13:40:18.070Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-63293 (GCVE-0-2026-63293)

    Vulnerability from cvelistv5 – Published: 2026-08-12 20:00 – Updated: 2026-08-13 12:40
    VLAI
    Title
    Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root
    Summary
    A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is a symbolic link. An attacker can exploit this flaw by providing a crafted image archive with a symlinked metadata.yaml file pointing to target file paths on the host system.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-13 12:39 UTC
    CWE
    • CWE-59 - Improper Link Resolution Before File Access ('Link Following')
    References
    URL Tags
    https://github.com/canonical/lxd/security/advisor… vdb-entryvendor-advisory
    Impacted products
    Vendor Product Version
    Canonical LXD Affected: 4.0.0 , < 4.0.12 (semver)
    Affected: 5.0.0 , < 5.0.8 (semver)
    Affected: 5.21.0 , < 5.21.6 (semver)
    Affected: 6.0 , < 6.10 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-63293",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-13T12:39:22.377281Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-13T12:40:35.947Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/canonical/lxd/security/advisories/GHSA-j825-cg34-5fr5"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "LXD",
              "platforms": [
                "Linux"
              ],
              "product": "LXD",
              "repo": "https://github.com/canonical/lxd",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "4.0.12",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.0.8",
                  "status": "affected",
                  "version": "5.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.21.6",
                  "status": "affected",
                  "version": "5.21.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.10",
                  "status": "affected",
                  "version": "6.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is a symbolic link. An attacker can exploit this flaw by providing a crafted image archive with a symlinked metadata.yaml file pointing to target file paths on the host system."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-132",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Symlink Attack"
                }
              ]
            },
            {
              "capecId": "CAPEC-153",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Input Data Manipulation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-59",
                  "description": "CWE-59 Improper Link Resolution Before File Access (\u0027Link Following\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-12T20:00:09.214Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "vdb-entry",
                "vendor-advisory"
              ],
              "url": "https://github.com/canonical/lxd/security/advisories/GHSA-j825-cg34-5fr5"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to LXD version 4.0.12 or later, 5.0.8 or later, or 5.12.6 or later, or 6.10 or later."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-63293",
        "datePublished": "2026-08-12T20:00:09.214Z",
        "dateReserved": "2026-07-16T09:49:29.911Z",
        "dateUpdated": "2026-08-13T12:40:35.947Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-63294 (GCVE-0-2026-63294)

    Vulnerability from cvelistv5 – Published: 2026-08-12 19:57 – Updated: 2026-08-13 12:38
    VLAI
    Title
    Root RCE via image backup.yaml symlink
    Summary
    A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml file when it exists as a symbolic link. An attacker can exploit this flaw by providing a malicious archive with a symlinked backup.yaml file, causing LXD to process unconfined configuration metadata and execute arbitrary commands with root privileges.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-13 12:38 UTC
    CWE
    • CWE-59 - Improper Link Resolution Before File Access ('Link Following')
    References
    URL Tags
    https://github.com/canonical/lxd/security/advisor… vdb-entryvendor-advisory
    Impacted products
    Vendor Product Version
    Canonical LXD Affected: 4.0.0 , < 4.0.12 (semver)
    Affected: 5.0.0 , < 5.0.8 (semver)
    Affected: 5.21.0 , < 5.21.6 (semver)
    Affected: 6.0 , < 6.10 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-63294",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-13T12:38:32.604341Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-13T12:38:48.134Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/canonical/lxd/security/advisories/GHSA-fv82-v4fj-mm4m"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "LXD",
              "platforms": [
                "Linux"
              ],
              "product": "LXD",
              "repo": "https://github.com/canonical/lxd",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "4.0.12",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.0.8",
                  "status": "affected",
                  "version": "5.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.21.6",
                  "status": "affected",
                  "version": "5.21.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.10",
                  "status": "affected",
                  "version": "6.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml file when it exists as a symbolic link. An attacker can exploit this flaw by providing a malicious archive with a symlinked backup.yaml file, causing LXD to process unconfined configuration metadata and execute arbitrary commands with root privileges."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-132",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Symlink Symbolic Link Execution"
                }
              ]
            },
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-59",
                  "description": "CWE-59 Improper Link Resolution Before File Access (\u0027Link Following\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-12T19:57:07.898Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "vdb-entry",
                "vendor-advisory"
              ],
              "url": "https://github.com/canonical/lxd/security/advisories/GHSA-fv82-v4fj-mm4m"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to LXD version 4.0.12 or later, 5.0.8 or later, or 5.12.6 or later, or 6.10 or later."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Root RCE via image backup.yaml symlink"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-63294",
        "datePublished": "2026-08-12T19:57:07.898Z",
        "dateReserved": "2026-07-16T09:49:29.911Z",
        "dateUpdated": "2026-08-13T12:38:48.134Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-63295 (GCVE-0-2026-63295)

    Vulnerability from cvelistv5 – Published: 2026-08-12 19:31 – Updated: 2026-08-13 14:24
    VLAI
    Title
    Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated`
    Summary
    An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as enforcing restricted.containers.privilege=isolated), LXD fails to enforce the requirement if an instance configuration omits the security.idmap.isolated key. An attacker can exploit this flaw by creating or updating an instance without explicitly setting security.idmap.isolated, bypassing the target project's security constraints.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-13 14:23 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    References
    URL Tags
    https://github.com/canonical/lxd/security/advisor… vdb-entryvendor-advisory
    Impacted products
    Vendor Product Version
    Canonical LXD Affected: 4.0.0 , < 4.0.12 (semver)
    Affected: 5.0.0 , < 5.0.8 (semver)
    Affected: 5.21.0 , < 5.21.6 (semver)
    Affected: 6.0 , < 6.10 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-63295",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-13T14:23:43.547083Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-13T14:24:15.556Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/canonical/lxd/security/advisories/GHSA-7vp9-3vmp-c5jm"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "LXD",
              "platforms": [
                "Linux"
              ],
              "product": "LXD",
              "repo": "https://github.com/canonical/lxd",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "4.0.12",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.0.8",
                  "status": "affected",
                  "version": "5.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.21.6",
                  "status": "affected",
                  "version": "5.21.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.10",
                  "status": "affected",
                  "version": "6.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as enforcing restricted.containers.privilege=isolated), LXD fails to enforce the requirement if an instance configuration omits the security.idmap.isolated key. An attacker can exploit this flaw by creating or updating an instance without explicitly setting security.idmap.isolated, bypassing the target project\u0027s security constraints."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-1",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Accessing Functionality Not Properly Constrained by ACLs"
                }
              ]
            },
            {
              "capecId": "CAPEC-122",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Privilege Abuse"
                }
              ]
            },
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "CWE-863 Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-12T19:31:32.323Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "vdb-entry",
                "vendor-advisory"
              ],
              "url": "https://github.com/canonical/lxd/security/advisories/GHSA-7vp9-3vmp-c5jm"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to LXD version 4.0.12 or later, 5.0.8 or later, or 5.12.6 or later, or 6.10 or later."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated`"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-63295",
        "datePublished": "2026-08-12T19:31:32.323Z",
        "dateReserved": "2026-07-16T09:49:29.911Z",
        "dateUpdated": "2026-08-13T14:24:15.556Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-63296 (GCVE-0-2026-63296)

    Vulnerability from cvelistv5 – Published: 2026-08-12 19:27 – Updated: 2026-08-13 14:25
    VLAI
    Title
    Project restriction bypass via instance migration config override
    Summary
    An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. An attacker can exploit this flaw to move instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-13 14:25 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    References
    URL Tags
    https://github.com/canonical/lxd/security/advisor… vdb-entryvendor-advisory
    Impacted products
    Vendor Product Version
    Canonical LXD Affected: 5.0.0 , < 5.0.8 (semver)
    Affected: 5.21.0 , < 5.21.6 (semver)
    Affected: 6.0 , < 6.10 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-63296",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-13T14:25:15.629982Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-13T14:25:39.478Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/canonical/lxd/security/advisories/GHSA-gcr9-5q6r-w625"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "LXD",
              "platforms": [
                "Linux"
              ],
              "product": "LXD",
              "repo": "https://github.com/canonical/lxd",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "5.0.8",
                  "status": "affected",
                  "version": "5.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.21.6",
                  "status": "affected",
                  "version": "5.21.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.10",
                  "status": "affected",
                  "version": "6.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project\u0027s enforced restrictions. An attacker can exploit this flaw to move instances with disallowed high-privilege configurations into restricted projects, bypassing security controls."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-1",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Accessing Functionality Not Properly Constrained by ACLs"
                }
              ]
            },
            {
              "capecId": "CAPEC-122",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Privilege Abuse"
                }
              ]
            },
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "CWE-863 Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-12T19:27:45.736Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "vdb-entry",
                "vendor-advisory"
              ],
              "url": "https://github.com/canonical/lxd/security/advisories/GHSA-gcr9-5q6r-w625"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to LXD version 5.0.8 or later, or 5.12.6 or later, or 6.10 or later."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Project restriction bypass via instance migration config override"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-63296",
        "datePublished": "2026-08-12T19:27:45.736Z",
        "dateReserved": "2026-07-16T09:49:29.911Z",
        "dateUpdated": "2026-08-13T14:25:39.478Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-63297 (GCVE-0-2026-63297)

    Vulnerability from cvelistv5 – Published: 2026-08-12 19:25 – Updated: 2026-08-13 14:29
    VLAI
    Title
    Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge
    Summary
    An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a target project, LXD performs restriction checks before configuration merging is complete, creating a time-of-check to time-of-use (TOCTOU) condition. An attacker can exploit this flaw to copy instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-13 14:28 UTC
    CWE
    • CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
    • CWE-863 - Incorrect Authorization
    References
    URL Tags
    https://github.com/canonical/lxd/security/advisor… vdb-entryvendor-advisory
    Impacted products
    Vendor Product Version
    Canonical LXD Affected: 5.0.0 , < 5.0.8 (semver)
    Affected: 5.21.0 , < 5.21.6 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-63297",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-13T14:28:52.383092Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-13T14:29:39.772Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/canonical/lxd/security/advisories/GHSA-v989-qw7w-xvg4"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "LXD",
              "platforms": [
                "Linux"
              ],
              "product": "LXD",
              "repo": "https://github.com/canonical/lxd",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "5.0.8",
                  "status": "affected",
                  "version": "5.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.21.6",
                  "status": "affected",
                  "version": "5.21.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a target project, LXD performs restriction checks before configuration merging is complete, creating a time-of-check to time-of-use (TOCTOU) condition. An attacker can exploit this flaw to copy instances with disallowed high-privilege configurations into restricted projects, bypassing security controls."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-1",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Accessing Functionality Not Properly Constrained by ACLs"
                }
              ]
            },
            {
              "capecId": "CAPEC-122",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Privilege Abuse"
                }
              ]
            },
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-367",
                  "description": "CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition",
                  "lang": "en",
                  "type": "CWE"
                },
                {
                  "cweId": "CWE-863",
                  "description": "CWE-863 Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-12T19:25:24.420Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "vdb-entry",
                "vendor-advisory"
              ],
              "url": "https://github.com/canonical/lxd/security/advisories/GHSA-v989-qw7w-xvg4"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to LXD version 5.0.8 or later, or 5.12.6 or later."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-63297",
        "datePublished": "2026-08-12T19:25:24.420Z",
        "dateReserved": "2026-07-16T09:49:29.911Z",
        "dateUpdated": "2026-08-13T14:29:39.772Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-63298 (GCVE-0-2026-63298)

    Vulnerability from cvelistv5 – Published: 2026-08-12 19:22 – Updated: 2026-08-13 14:33
    VLAI
    Title
    LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration
    Summary
    An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or 'nvidia.require.*' configuration values, an attacker can manipulate the generated lxc.conf file. This flaw enables the attacker to execute arbitrary code on the host system with the privileges of the LXD daemon.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-13 14:33 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    URL Tags
    https://github.com/canonical/lxd/security/advisor… vdb-entryvendor-advisory
    Impacted products
    Vendor Product Version
    Canonical LXD Affected: 5.0.0 , < 5.0.8 (semver)
    Affected: 5.21.0 , < 5.21.6 (semver)
    Affected: 4.0.0 , < 4.0.12 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-63298",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-13T14:33:35.469940Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-13T14:33:57.467Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/canonical/lxd/security/advisories/GHSA-vfh7-q59q-54v2"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "LXD",
              "platforms": [
                "Linux"
              ],
              "product": "LXD",
              "repo": "https://github.com/canonical/lxd",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "5.0.8",
                  "status": "affected",
                  "version": "5.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.21.6",
                  "status": "affected",
                  "version": "5.21.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "4.0.12",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An improper neutralization of special elements vulnerability in LXD\u0027s NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the \u0027nvidia.driver.capabilities\u0027 or \u0027nvidia.require.*\u0027 configuration values, an attacker can manipulate the generated lxc.conf file. This flaw enables the attacker to execute arbitrary code on the host system with the privileges of the LXD daemon."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-81",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Input Data Manipulation"
                }
              ]
            },
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-12T19:22:07.286Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "vdb-entry",
                "vendor-advisory"
              ],
              "url": "https://github.com/canonical/lxd/security/advisories/GHSA-vfh7-q59q-54v2"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to LXD version 4.0.12 or later, 5.0.8 or later, or 5.12.6 or later."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-63298",
        "datePublished": "2026-08-12T19:22:07.286Z",
        "dateReserved": "2026-07-16T09:49:29.911Z",
        "dateUpdated": "2026-08-13T14:33:57.467Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-63299 (GCVE-0-2026-63299)

    Vulnerability from cvelistv5 – Published: 2026-08-12 19:17 – Updated: 2026-08-12 19:26
    VLAI
    Title
    Storage volume cross-project move and snapshot restore bypass project disk limits
    Summary
    An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations: the storagePoolVolumeTypePostMove function omits the limits.AllowVolumeCreation check before moving a volume across projects, and volume snapshot restore operations skip the AllowVolumeUpdate check when the configuration is nil (Config == nil). An attacker can exploit these flaws to allocate storage resources that exceed the administrative limits configured for a project.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-12 19:26 UTC
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    References
    URL Tags
    https://github.com/canonical/lxd/security/advisor… vdb-entryvendor-advisory
    Impacted products
    Vendor Product Version
    Canonical LXD Affected: 5.0.0 , < 5.0.8 (semver)
    Affected: 5.21.0 , < 5.21.6 (semver)
    Affected: 6.0 , < 6.10 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-63299",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-12T19:26:19.187565Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-12T19:26:28.110Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "LXD",
              "platforms": [
                "Linux"
              ],
              "product": "LXD",
              "repo": "https://github.com/canonical/lxd",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "5.0.8",
                  "status": "affected",
                  "version": "5.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.21.6",
                  "status": "affected",
                  "version": "5.21.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.10",
                  "status": "affected",
                  "version": "6.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations: the storagePoolVolumeTypePostMove function omits the limits.AllowVolumeCreation check before moving a volume across projects, and volume snapshot restore operations skip the AllowVolumeUpdate check when the configuration is nil (Config == nil). An attacker can exploit these flaws to allocate storage resources that exceed the administrative limits configured for a project."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-1",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Accessing Functionality Not Properly Constrained by ACLs"
                }
              ]
            },
            {
              "capecId": "CAPEC-122",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Privilege Abuse"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "CWE-770 Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-12T19:17:07.418Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "vdb-entry",
                "vendor-advisory"
              ],
              "url": "https://github.com/canonical/lxd/security/advisories/GHSA-5h78-p252-989h"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to LXD version 5.0.8 or later, 5.21.6 or later, or 6.10 or later."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Storage volume cross-project move and snapshot restore bypass project disk limits"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-63299",
        "datePublished": "2026-08-12T19:17:07.418Z",
        "dateReserved": "2026-07-16T10:01:05.653Z",
        "dateUpdated": "2026-08-12T19:26:28.110Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-62420 (GCVE-0-2026-62420)

    Vulnerability from cvelistv5 – Published: 2026-08-12 19:12 – Updated: 2026-08-12 19:27
    VLAI
    Title
    Cross-project cluster migration bypasses project restrictions via cluster notification flag
    Summary
    An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: <target>, and target: <member>, the destination node skips all project restriction checks because the request arrives as an internal cluster notification. An attacker can exploit this to introduce disallowed instance configurations into a restricted project.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-12 19:26 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    Canonical LXD Affected: 5.0.0 , < 5.0.8 (semver)
    Affected: 5.21.0 , < 5.21.6 (semver)
    Affected: 6.0 , < 6.10 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-62420",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-12T19:26:54.388067Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-12T19:27:44.371Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/canonical/lxd/security/advisories/GHSA-v9wr-9r7q-fh4g"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "LXD",
              "platforms": [
                "Linux"
              ],
              "product": "LXD",
              "repo": "https://github.com/canonical/lxd",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "5.0.8",
                  "status": "affected",
                  "version": "5.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.21.6",
                  "status": "affected",
                  "version": "5.21.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.10",
                  "status": "affected",
                  "version": "6.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: \u003ctarget\u003e, and target: \u003cmember\u003e, the destination node skips all project restriction checks because the request arrives as an internal cluster notification. An attacker can exploit this to introduce disallowed instance configurations into a restricted project."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-180",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Exploiting Incorrectly Configured Access Control Security Levels"
                }
              ]
            },
            {
              "capecId": "CAPEC-122",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Privilege Abuse"
                }
              ]
            },
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "CWE-863 Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-12T19:12:28.097Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "vdb-entry",
                "vendor-advisory"
              ],
              "url": "https://github.com/canonical/lxd/security/advisories/GHSA-v9wr-9r7q-fh4g"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/lxd/pull/18651"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/lxd/pull/18605"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to LXD version 5.0.8 or later, 5.21.6 or later, or 6.10 or later."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Cross-project cluster migration bypasses project restrictions via cluster notification flag"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-62420",
        "datePublished": "2026-08-12T19:12:28.097Z",
        "dateReserved": "2026-07-14T08:57:47.667Z",
        "dateUpdated": "2026-08-12T19:27:44.371Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-63300 (GCVE-0-2026-63300)

    Vulnerability from cvelistv5 – Published: 2026-08-12 19:09 – Updated: 2026-08-13 13:19
    VLAI
    Title
    Cross-project instance move bypasses all project restrictions allowing host command execution
    Summary
    An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security restrictions. When migrating an instance between projects, LXD fails to validate the instance's configuration against the target project's enforced restrictions (such as restricted.containers.lowlevel, restricted.devices.*, and restricted.networks.access). An attacker can exploit this by creating a disallowed or high-privilege instance in an unrestricted project and subsequently moving it into the restricted project.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-13 03:55 UTC
    CWE
    Impacted products
    Vendor Product Version
    Canonical LXD Affected: 5.0.0 , < 5.0.8 (semver)
    Affected: 5.21.0 , < 5.21.6 (semver)
    Affected: 6.0 , < 6.10 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-63300",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-13T03:55:57.925616Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-13T13:19:51.113Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "LXD",
              "platforms": [
                "Linux"
              ],
              "product": "LXD",
              "repo": "https://github.com/canonical/lxd",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "5.0.8",
                  "status": "affected",
                  "version": "5.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.21.6",
                  "status": "affected",
                  "version": "5.21.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.10",
                  "status": "affected",
                  "version": "6.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security restrictions. When migrating an instance between projects, LXD fails to validate the instance\u0027s configuration against the target project\u0027s enforced restrictions (such as restricted.containers.lowlevel, restricted.devices.*, and restricted.networks.access). An attacker can exploit this by creating a disallowed or high-privilege instance in an unrestricted project and subsequently moving it into the restricted project."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-180",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Exploiting Incorrectly Configured Access Control Security Levels"
                }
              ]
            },
            {
              "capecId": "CAPEC-122",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Privilege Abuse"
                }
              ]
            },
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-12T19:09:04.445Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "vdb-entry",
                "vendor-advisory"
              ],
              "url": "https://github.com/canonical/lxd/security/advisories/GHSA-5g5r-wh97-qcq2"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/lxd/pull/18651"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/canonical/lxd/pull/18605"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to LXD version 5.0.8 or later, 5.21.6 or later, or 6.10 or later."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Cross-project instance move bypasses all project restrictions allowing host command execution"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-63300",
        "datePublished": "2026-08-12T19:09:04.445Z",
        "dateReserved": "2026-07-16T10:01:05.653Z",
        "dateUpdated": "2026-08-13T13:19:51.113Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-8933 (GCVE-0-2026-8933)

    Vulnerability from cvelistv5 – Published: 2026-07-21 14:02 – Updated: 2026-07-22 18:28
    VLAI
    Title
    snap-confine Local Privilege Escalation via Capabilities Misconfiguration or Flaw in Execution Environment Setup
    Summary
    A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-22 18:15 UTC
    CWE
    • CWE-250 - Execution with unnecessary privileges
    References
    URL Tags
    https://ubuntu.com/security/CVE-2026-8933 vdb-entryissue-tracking
    Impacted products
    Vendor Product Version
    Affected: 2.75.0 , < 2.76.1 (semver)
    Canonical Ubuntu 26.04 LTS Unaffected: 2.76+ubuntu26.04.3 (dpkg)
    Create a notification for this product.
    Canonical Ubuntu 24.04 LTS Unaffected: 2.76+ubuntu24.04.1 (dpkg)
    Create a notification for this product.
    Canonical Ubuntu 22.04 LTS Unaffected: 2.76+ubuntu22.04.1 (dpkg)
    Create a notification for this product.
    Date Public
    2026-07-21 02:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-8933",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-22T18:15:11.199548Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-22T18:28:05.924Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://github.com/canonical",
              "defaultStatus": "unaffected",
              "packageName": "snapd",
              "repo": "https://github.com/canonical/snapd/",
              "versions": [
                {
                  "lessThan": "2.76.1",
                  "status": "affected",
                  "version": "2.75.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/resolute",
              "defaultStatus": "affected",
              "packageName": "snapd",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 26.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/snapd",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "2.76+ubuntu26.04.3",
                  "versionType": "dpkg"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/noble",
              "defaultStatus": "affected",
              "packageName": "snapd",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 24.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/snapd",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "2.76+ubuntu24.04.1",
                  "versionType": "dpkg"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/jammy",
              "defaultStatus": "affected",
              "packageName": "snapd",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 22.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/snapd",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "2.76+ubuntu22.04.1",
                  "versionType": "dpkg"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Qualys Security Advisory Team"
            }
          ],
          "datePublic": "2026-07-21T02:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations).\nDue to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-233 Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-250",
                  "description": "CWE-250 Execution with unnecessary privileges",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-21T14:02:19.758Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "vdb-entry",
                "issue-tracking"
              ],
              "url": "https://ubuntu.com/security/CVE-2026-8933"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "snap-confine Local Privilege Escalation via Capabilities Misconfiguration or Flaw in Execution Environment Setup"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-8933",
        "datePublished": "2026-07-21T14:02:19.758Z",
        "dateReserved": "2026-05-19T10:37:03.649Z",
        "dateUpdated": "2026-07-22T18:28:05.924Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-15226 (GCVE-0-2026-15226)

    Vulnerability from cvelistv5 – Published: 2026-07-21 14:02 – Updated: 2026-07-22 18:28
    VLAI
    Title
    snapd snap-confine Sandbox Confinement Bypass via Omission of setuid Restriction in Seccomp Templates
    Summary
    A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler (snap-confine). The default seccomp security templates generated by the engine to restrict system calls do not filter or reject process operations capable of creating or manipulating file execution flags with set-user-ID attributes. Consequently, an application running within a strictly confined snap environment can successfully compile or drop binaries and apply setuid properties to them. If a compromised or malicious process inside the snap sandbox executes these generated setuid binaries, it can potentially circumvent architectural sandboxing assumptions, drop intended restriction policies, or execute privileged actions inside the container namespace that should otherwise be strictly blocked. The vulnerability has been resolved by hardening the seccomp template engine to block the execution and creation of setuid executables by sandboxed snap processes.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-22 18:15 UTC
    CWE
    • CWE-250 - Execution with unnecessary privileges
    References
    URL Tags
    https://ubuntu.com/security/CVE-2026-15226 vdb-entryissue-tracking
    Impacted products
    Vendor Product Version
    Affected: 0 , < 2.76.1 (semver)
    Canonical Ubuntu 26.04 LTS Unaffected: 2.76+ubuntu26.04.3 (dpkg)
    Create a notification for this product.
    Canonical Ubuntu 24.04 LTS Unaffected: 2.76+ubuntu24.04.1 (dpkg)
    Create a notification for this product.
    Canonical Ubuntu 22.04 LTS Unaffected: 2.76+ubuntu22.04.1 (dpkg)
    Create a notification for this product.
    Canonical Ubuntu 20.04 LTS Unaffected: 2.67.1+20.04ubuntu1~esm2 (dpkg)
    Create a notification for this product.
    Canonical Ubuntu 18.04 LTS Unaffected: 2.61.4ubuntu0.18.04.1+esm3 (dpkg)
    Create a notification for this product.
    Canonical Ubuntu 16.04 LTS Unaffected: 2.61.4ubuntu0.16.04.1+esm3
    Create a notification for this product.
    Date Public
    2026-07-21 14:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-15226",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-22T18:15:09.916257Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-22T18:28:11.440Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://github.com/canonical",
              "defaultStatus": "unaffected",
              "packageName": "snapd",
              "repo": "https://github.com/canonical/snapd/",
              "versions": [
                {
                  "lessThan": "2.76.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/resolute",
              "defaultStatus": "affected",
              "packageName": "snapd",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 26.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/snapd",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "2.76+ubuntu26.04.3",
                  "versionType": "dpkg"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/noble",
              "defaultStatus": "affected",
              "packageName": "snapd",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 24.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/snapd",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "2.76+ubuntu24.04.1",
                  "versionType": "dpkg"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/jammy",
              "defaultStatus": "affected",
              "packageName": "snapd",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 22.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/snapd",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "2.76+ubuntu22.04.1",
                  "versionType": "dpkg"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/focal",
              "defaultStatus": "affected",
              "packageName": "snapd",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 20.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/snapd",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "2.67.1+20.04ubuntu1~esm2",
                  "versionType": "dpkg"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/bionic",
              "defaultStatus": "affected",
              "packageName": "snapd",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 18.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/snapd",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "2.61.4ubuntu0.18.04.1+esm3",
                  "versionType": "dpkg"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/xenial",
              "defaultStatus": "affected",
              "packageName": "snapd",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 16.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/snapd",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "2.61.4ubuntu0.16.04.1+esm3"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Zygmunt Krynicki"
            }
          ],
          "datePublic": "2026-07-21T14:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler (snap-confine). The default seccomp security templates generated by the engine to restrict system calls do not filter or reject process operations capable of creating or manipulating file execution flags with set-user-ID attributes.  Consequently, an application running within a strictly confined snap environment can successfully compile or drop binaries and apply setuid properties to them. If a compromised or malicious process inside the snap sandbox executes these generated setuid binaries, it can potentially circumvent architectural sandboxing assumptions, drop intended restriction policies, or execute privileged actions inside the container namespace that should otherwise be strictly blocked. The vulnerability has been resolved by hardening the seccomp template engine to block the execution and creation of setuid executables by sandboxed snap processes."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-122",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-122 Privilege Abuse"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 8.4,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-250",
                  "description": "CWE-250 Execution with unnecessary privileges",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-21T14:02:04.071Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "vdb-entry",
                "issue-tracking"
              ],
              "url": "https://ubuntu.com/security/CVE-2026-15226"
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "snapd snap-confine Sandbox Confinement Bypass via Omission of setuid Restriction in Seccomp Templates"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-15226",
        "datePublished": "2026-07-21T14:02:04.071Z",
        "dateReserved": "2026-07-09T10:14:23.078Z",
        "dateUpdated": "2026-07-22T18:28:11.440Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-5300 (GCVE-0-2024-5300)

    Vulnerability from cvelistv5 – Published: 2026-07-21 14:00 – Updated: 2026-07-22 18:28
    VLAI
    Title
    AppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauthorized Access to Hashed Passwords via systemd-userdbd
    Summary
    An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd (inherited via ) inadvertently permit strictly confined snap applications, which lack the privileged account-control interface, to interact directly with the io.systemd.Multiplexer and io.systemd.NameServiceSwitch UNIX domain sockets under /run/systemd/userdb/. On systems where the systemd-userdbd service is installed and operational, the service fails to distinguish between an unconfined root user on the host system and a restricted root user running within a snap application's sandbox (such as a daemon or configuration hook). Because systemd-userdbd returns "complete" user records—including sensitive hashed user passwords from /etc/shadow—when queried by a process running as root, a compromised or malicious strictly confined snap executing code as root can successfully query the Varlink interface to retrieve all system password hashes, bypassing intended snap sandbox restrictions. This issue is mitigated by the fact that systemd-userdbd is not installed by default on standard Ubuntu deployments.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-22 18:13 UTC
    CWE
    • CWE-212 - Improper removal of sensitive information before storage or transfer
    References
    URL Tags
    https://ubuntu.com/security/CVE-2024-5300 vdb-entryissue-tracking
    Impacted products
    Vendor Product Version
    Affected: 0 , < 2.76.1 (semver)
    Canonical Ubuntu 26.04 LTS Unaffected: 2.76+ubuntu26.04.3 (dpkg)
    Create a notification for this product.
    Canonical Ubuntu 24.04 LTS Unaffected: 2.76+ubuntu24.04.1 (dpkg)
    Create a notification for this product.
    Canonical Ubuntu 22.04 LTS Unaffected: 2.76+ubuntu22.04.1 (dpkg)
    Create a notification for this product.
    Canonical Ubuntu 20.04 LTS Unaffected: 2.67.1+20.04ubuntu1~esm2 (dpkg)
    Create a notification for this product.
    Canonical Ubuntu 18.04 LTS Unaffected: 2.61.4ubuntu0.18.04.1+esm3 (dpkg)
    Create a notification for this product.
    Canonical Ubuntu 16.04 LTS Unaffected: 2.61.4ubuntu0.16.04.1+esm3
    Create a notification for this product.
    Date Public
    2026-07-21 14:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-5300",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-22T18:13:29.966474Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-22T18:28:16.818Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://github.com/canonical",
              "defaultStatus": "unaffected",
              "packageName": "snapd",
              "repo": "https://github.com/canonical/snapd/",
              "versions": [
                {
                  "lessThan": "2.76.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/resolute",
              "defaultStatus": "affected",
              "packageName": "snapd",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 26.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/snapd",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "2.76+ubuntu26.04.3",
                  "versionType": "dpkg"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/noble",
              "defaultStatus": "affected",
              "packageName": "snapd",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 24.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/snapd",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "2.76+ubuntu24.04.1",
                  "versionType": "dpkg"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/jammy",
              "defaultStatus": "affected",
              "packageName": "snapd",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 22.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/snapd",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "2.76+ubuntu22.04.1",
                  "versionType": "dpkg"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/focal",
              "defaultStatus": "affected",
              "packageName": "snapd",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 20.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/snapd",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "2.67.1+20.04ubuntu1~esm2",
                  "versionType": "dpkg"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/bionic",
              "defaultStatus": "affected",
              "packageName": "snapd",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 18.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/snapd",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "2.61.4ubuntu0.18.04.1+esm3",
                  "versionType": "dpkg"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/xenial",
              "defaultStatus": "affected",
              "packageName": "snapd",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 16.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/snapd",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "2.61.4ubuntu0.16.04.1+esm3"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "James Henstridge"
            }
          ],
          "datePublic": "2026-07-21T14:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd (inherited via ) inadvertently permit strictly confined snap applications, which lack the privileged account-control interface, to interact directly with the io.systemd.Multiplexer and io.systemd.NameServiceSwitch UNIX domain sockets under /run/systemd/userdb/.\nOn systems where the systemd-userdbd service is installed and operational, the service fails to distinguish between an unconfined root user on the host system and a restricted root user running within a snap application\u0027s sandbox (such as a daemon or configuration hook). Because systemd-userdbd returns \"complete\" user records\u2014including sensitive hashed user passwords from /etc/shadow\u2014when queried by a process running as root, a compromised or malicious strictly confined snap executing code as root can successfully query the Varlink interface to retrieve all system password hashes, bypassing intended snap sandbox restrictions. This issue is mitigated by the fact that systemd-userdbd is not installed by default on standard Ubuntu deployments."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-1",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 5.6,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-212",
                  "description": "CWE-212 Improper removal of sensitive information before storage or transfer",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-21T14:00:51.066Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "vdb-entry",
                "issue-tracking"
              ],
              "url": "https://ubuntu.com/security/CVE-2024-5300"
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "AppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauthorized Access to Hashed Passwords via systemd-userdbd"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2024-5300",
        "datePublished": "2026-07-21T14:00:51.066Z",
        "dateReserved": "2024-05-23T21:58:22.809Z",
        "dateUpdated": "2026-07-22T18:28:16.818Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-12391 (GCVE-0-2026-12391)

    Vulnerability from cvelistv5 – Published: 2026-07-16 12:17 – Updated: 2026-07-16 13:28
    VLAI
    Title
    ubuntu-pro-client Local Privilege Escalation and Information Disclosure via Symlink Arbitrary File Read in collect-logs
    Summary
    An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file paths or user-accessible log directories when gathering diagnostic information without verifying the file type or ownership. An unprivileged local attacker can exploit this behavior by creating a symbolic link (symlink) at a predictable destination path pointing to an arbitrary, root-readable file (such as /etc/shadow or private files within /root). When a root administrator or operator subsequently executes the pro collect-logs command, the tool follows the user-controlled symlink, reads the target file, and compresses its contents into the resulting diagnostic support archive. Because the output archive remains readable by the unprivileged user, the attacker can extract and read the sensitive root-owned files, leading to a complete information disclosure of system secrets.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-16 13:20 UTC
    CWE
    • CWE-59 - Improper link resolution before file access ('link following')
    References
    Date Public
    2026-07-16 12:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-12391",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-16T13:20:30.714803Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-16T13:28:19.156Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://github.com/canonical/",
              "defaultStatus": "unaffected",
              "packageName": "ubuntu-pro-client",
              "platforms": [
                "Linux"
              ],
              "product": "ubuntu-pro-client (ubuntu-advantage-tools)",
              "repo": "https://github.com/canonical/ubuntu-pro-client",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "37.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "python"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/resolute",
              "defaultStatus": "affected",
              "packageName": "ubuntu-advantage-tools",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 26.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/ubuntu-advantage-tools",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "37.2ubuntu0.1",
                  "versionType": "dpkg"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/noble",
              "defaultStatus": "affected",
              "packageName": "ubuntu-advantage-tools",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 24.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/ubuntu-advantage-tools",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "37.2ubuntu~24.04.1",
                  "versionType": "dpkg"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/jammy",
              "defaultStatus": "affected",
              "packageName": "ubuntu-advantage-tools",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 22.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/ubuntu-advantage-tools",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "37.2ubuntu~22.04.1",
                  "versionType": "dpkg"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/focal",
              "defaultStatus": "affected",
              "packageName": "ubuntu-advantage-tools",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 20.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/ubuntu-advantage-tools",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "37.1ubuntu0~20.04.1",
                  "versionType": "dpkg"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/bionic",
              "defaultStatus": "affected",
              "packageName": "ubuntu-advantage-tools",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 18.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/ubuntu-advantage-tools",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "37.1ubuntu0~18.04.1",
                  "versionType": "dpkg"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/xenial",
              "defaultStatus": "affected",
              "packageName": "ubuntu-advantage-tools",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 16.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/ubuntu-advantage-tools",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "37.1ubuntu0~16.04.1",
                  "versionType": "dpkg"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Mateusz Gierblinski"
            }
          ],
          "datePublic": "2026-07-16T12:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An insecure symlink following vulnerability exists in Canonical\u003cbr\u003eubuntu-pro-client (formerly ubuntu-advantage-tools) within the\u003cbr\u003epro collect-logs command framework. The utility creates or utilizes\u003cbr\u003epredictable temporary file paths or user-accessible log directories when\u003cbr\u003egathering diagnostic information without verifying the file type or ownership.\u003cbr\u003eAn unprivileged local attacker can exploit this behavior by creating a\u003cbr\u003esymbolic link (symlink) at a predictable destination path pointing to an\u003cbr\u003earbitrary, root-readable file (such as /etc/shadow or private files within\u003cbr\u003e/root).\u003cbr\u003eWhen a root administrator or operator subsequently executes the\u003cbr\u003epro collect-logs command, the tool follows the user-controlled symlink, reads\u003cbr\u003ethe target file, and compresses its contents into the resulting diagnostic\u003cbr\u003esupport archive. Because the output archive remains readable by the\u003cbr\u003eunprivileged user, the attacker can extract and read the sensitive root-owned\u003cbr\u003efiles, leading to a complete information disclosure of system secrets.\u003cbr\u003e"
                }
              ],
              "value": "An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file paths or user-accessible log directories when gathering diagnostic information without verifying the file type or ownership. An unprivileged local attacker can exploit this behavior by creating a symbolic link (symlink) at a predictable destination path pointing to an arbitrary, root-readable file (such as /etc/shadow or private files within /root). When a root administrator or operator subsequently executes the pro collect-logs command, the tool follows the user-controlled symlink, reads the target file, and compresses its contents into the resulting diagnostic support archive. Because the output archive remains readable by the unprivileged user, the attacker can extract and read the sensitive root-owned files, leading to a complete information disclosure of system secrets."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-132",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-132 Symlink Attack"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-59",
                  "description": "CWE-59 Improper link resolution before file access (\u0027link following\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-16T12:17:01.094Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "vdb-entry"
              ],
              "url": "https://ubuntu.com/security/CVE-2026-12391"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "ubuntu-pro-client Local Privilege Escalation and Information Disclosure via Symlink Arbitrary File Read in collect-logs"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-12391",
        "datePublished": "2026-07-16T12:17:01.094Z",
        "dateReserved": "2026-06-16T12:15:12.153Z",
        "dateUpdated": "2026-07-16T13:28:19.156Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-11386 (GCVE-0-2026-11386)

    Vulnerability from cvelistv5 – Published: 2026-07-16 12:16 – Updated: 2026-07-16 13:31
    VLAI
    Title
    ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injection and Remote Code Execution
    Summary
    An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline character filtering, a malicious or tampered contract response containing embedded newline (\n) characters can successfully inject arbitrary, attacker-controlled deb configuration lines into root-owned APT sources. When combined with the unvalidated additionalPackages[] field—which is passed positionally into a root-executed apt-get install command—an attacker capable of spoofing or manipulating the contract response (e.g., via a compromised internal infrastructure, an intercepted connection utilizing a trusted CA, or local logical bugs) can force the client to fetch and install malicious packages. This ultimately leads to arbitrary code execution with root privileges on the affected system. This component is preinstalled on supported Ubuntu Server releases and auto-attaches by default on cloud provider Ubuntu Pro images.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-16 13:30 UTC
    CWE
    • CWE-20 - Improper input validation
    References
    Date Public
    2026-07-16 12:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-11386",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-16T13:30:45.443694Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-16T13:31:16.910Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://github.com/canonical/",
              "defaultStatus": "unaffected",
              "packageName": "ubuntu-pro-client",
              "platforms": [
                "Linux"
              ],
              "product": "ubuntu-pro-client (ubuntu-advantage-tools)",
              "repo": "https://github.com/canonical/ubuntu-pro-client",
              "vendor": "Canonical",
              "versions": [
                {
                  "lessThan": "37.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "python"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/resolute",
              "defaultStatus": "affected",
              "packageName": "ubuntu-advantage-tools",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 26.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/ubuntu-advantage-tools",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "37.2ubuntu0.1",
                  "versionType": "dpkg"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/noble",
              "defaultStatus": "affected",
              "packageName": "ubuntu-advantage-tools",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 24.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/ubuntu-advantage-tools",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "37.2ubuntu~24.04.1",
                  "versionType": "dpkg"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/jammy",
              "defaultStatus": "affected",
              "packageName": "ubuntu-advantage-tools",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 22.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/ubuntu-advantage-tools",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "37.2ubuntu~22.04.1",
                  "versionType": "dpkg"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/focal",
              "defaultStatus": "affected",
              "packageName": "ubuntu-advantage-tools",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 20.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/ubuntu-advantage-tools",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "37.1ubuntu0~20.04.1",
                  "versionType": "dpkg"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/bionic",
              "defaultStatus": "affected",
              "packageName": "ubuntu-advantage-tools",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 18.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/ubuntu-advantage-tools",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "37.1ubuntu0~18.04.1",
                  "versionType": "dpkg"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/xenial",
              "defaultStatus": "affected",
              "packageName": "ubuntu-advantage-tools",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 16.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/ubuntu-advantage-tools",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "37.1ubuntu0~16.04.1",
                  "versionType": "dpkg"
                }
              ]
            },
            {
              "collectionURL": "https://launchpad.net/ubuntu/trusty",
              "defaultStatus": "affected",
              "packageName": "ubuntu-advantage-tools",
              "platforms": [
                "Linux"
              ],
              "product": "Ubuntu 14.04 LTS",
              "repo": "https://launchpad.net/ubuntu/+source/ubuntu-advantage-tools",
              "vendor": "Canonical",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "19.7ubuntu0.1",
                  "versionType": "dpkg"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Frederick Jerusha"
            }
          ],
          "datePublic": "2026-07-16T12:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An input validation and injection vulnerability exists in Canonical\u003cbr\u003eubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs\u003cbr\u003eAPT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their\u003cbr\u003eDEB822 equivalents) using data received directly from the contract server\u003cbr\u003eresponse via the directives.suites[] and directives.aptURL fields. Because\u003cbr\u003ethe client utilizes Python\u0027s str.format() to write these files without\u003cbr\u003eperforming escaping, validation, or newline character filtering, a malicious\u003cbr\u003eor tampered contract response containing embedded newline (\\n) characters can\u003cbr\u003esuccessfully inject arbitrary, attacker-controlled deb configuration lines into\u003cbr\u003eroot-owned APT sources.\u003cbr\u003eWhen combined with the unvalidated additionalPackages[] field\u2014which is passed\u003cbr\u003epositionally into a root-executed apt-get install command\u2014an attacker capable of\u003cbr\u003espoofing or manipulating the contract response (e.g., via a compromised internal\u003cbr\u003einfrastructure, an intercepted connection utilizing a trusted CA, or local logical\u003cbr\u003ebugs) can force the client to fetch and install malicious packages. This ultimately\u003cbr\u003eleads to arbitrary code execution with root privileges on the affected system. This\u003cbr\u003ecomponent is preinstalled on supported Ubuntu Server releases and auto-attaches by\u003cbr\u003edefault on cloud provider Ubuntu Pro images."
                }
              ],
              "value": "An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python\u0027s str.format() to write these files without performing escaping, validation, or newline character filtering, a malicious or tampered contract response containing embedded newline (\\n) characters can successfully inject arbitrary, attacker-controlled deb configuration lines into root-owned APT sources. When combined with the unvalidated additionalPackages[] field\u2014which is passed positionally into a root-executed apt-get install command\u2014an attacker capable of spoofing or manipulating the contract response (e.g., via a compromised internal infrastructure, an intercepted connection utilizing a trusted CA, or local logical bugs) can force the client to fetch and install malicious packages. This ultimately leads to arbitrary code execution with root privileges on the affected system. This component is preinstalled on supported Ubuntu Server releases and auto-attaches by default on cloud provider Ubuntu Pro images."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-242",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-242 Code Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper input validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-16T12:16:02.508Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "vdb-entry"
              ],
              "url": "https://ubuntu.com/security/CVE-2026-11386"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injection and Remote Code Execution"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2026-11386",
        "datePublished": "2026-07-16T12:16:02.508Z",
        "dateReserved": "2026-06-05T15:11:57.169Z",
        "dateUpdated": "2026-07-16T13:31:16.910Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }