Search
Find a vulnerability
Search criteria
8551 vulnerabilities by canonical
CVE-2026-102371 (GCVE-0-2026-102371)
Vulnerability from nvd – Published: 2026-09-29 14:11 – Updated: 2026-09-30 15:28
VLAI
EPSS
VEX
Title
wsl-pro-service: Ubuntu Pro token exposed via process command-line arguments
Summary
In wsl-pro-service before 0.1.19ubuntu3, the service component which runs as root inside each WSL instance attaches the instance to Ubuntu Pro by executing the pro client with the Ubuntu Pro token passed as a command-line argument (pro attach <token>). On systems where /proc is mounted without process-hiding mitigations (such as hidepid), which is the default in WSL, an unprivileged local user or process in the same WSL instance can read the token from /proc/<pid>/cmdline while the attach process is running. The leaked token could then be used to attach other machines to the victim's Ubuntu Pro subscription and gain unauthorized access to Ubuntu Pro services.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 15:17 UTC
CWE
- CWE-214 - Invocation of process using visible sensitive information
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/canonical/ubuntu-pro-for-wsl/p… | patch |
| https://github.com/canonical/ubuntu-pro-for-wsl/c… | patch |
| https://ubuntu.com/security/CVE-2026-102371 | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Canonical | Ubuntu Pro for WSL |
Affected:
0.1.1 , < 0.1.19ubuntu2
(ubuntu-resolute)
Affected: 0.1.1 , < 0.1.18~24.04.3 (ubuntu-noble) Affected: 0.1.1 , < 0.1.18~22.04.2 (ubuntu-jammy) Affected: 0.1.1 , < 0.1.18~20.04.2 (ubuntu-focal) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102371",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T15:17:31.871369Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T15:28:19.783Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "wsl-pro-service",
"platforms": [
"Linux"
],
"product": "Ubuntu Pro for WSL",
"repo": "https://github.com/canonical/ubuntu-pro-for-wsl",
"vendor": "Canonical",
"versions": [
{
"lessThan": "0.1.19ubuntu2",
"status": "affected",
"version": "0.1.1",
"versionType": "ubuntu-resolute"
},
{
"lessThan": "0.1.18~24.04.3",
"status": "affected",
"version": "0.1.1",
"versionType": "ubuntu-noble"
},
{
"lessThan": "0.1.18~22.04.2",
"status": "affected",
"version": "0.1.1",
"versionType": "ubuntu-jammy"
},
{
"lessThan": "0.1.18~20.04.2",
"status": "affected",
"version": "0.1.1",
"versionType": "ubuntu-focal"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Darshan U"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Carlos Nihelton"
}
],
"descriptions": [
{
"lang": "en",
"value": "In wsl-pro-service before 0.1.19ubuntu3, the service component which runs as root inside each WSL instance attaches the instance to Ubuntu Pro by executing the pro client with the Ubuntu Pro token passed as a command-line argument (pro attach \u003ctoken\u003e). On systems where /proc is mounted without process-hiding mitigations (such as hidepid), which is the default in WSL, an unprivileged local user or process in the same WSL instance can read the token from /proc/\u003cpid\u003e/cmdline while the attach process is running. The leaked token could then be used to attach other machines to the victim\u0027s Ubuntu Pro subscription and gain unauthorized access to Ubuntu Pro services."
}
],
"impacts": [
{
"capecId": "CAPEC-639",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-639 Probe System Files"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "LOCAL",
"baseScore": 5.7,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-214",
"description": "CWE-214 Invocation of process using visible sensitive information",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T14:11:19.350Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/ubuntu-pro-for-wsl/pull/1816"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/ubuntu-pro-for-wsl/commit/11c164a37b806bcf2a2304beb0d65e406739778b"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://ubuntu.com/security/CVE-2026-102371"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "wsl-pro-service: Ubuntu Pro token exposed via process command-line arguments",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-102371",
"datePublished": "2026-09-29T14:11:19.350Z",
"dateReserved": "2026-09-28T23:44:11.787Z",
"dateUpdated": "2026-09-30T15:28:19.783Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-97335 (GCVE-0-2026-97335)
Vulnerability from nvd – Published: 2026-09-28 13:22 – Updated: 2026-09-28 16:32
VLAI
EPSS
VEX
Title
Incorrect authorization in LXD storage volume API allows reading volumes from other projects
Summary
Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create custom volumes in a project to copy, and so read, any custom storage volume from any other project on the server, including its snapshots and configuration. The client does this with a crafted request that sets a source volume and source.project but omits source.type.
Severity
7.7 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-28 14:02 UTC
CWE
- CWE-863 - Incorrect Authorization
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://github.com/canonical/lxd/security/advisor… | vendor-advisory |
Impacted products
Date Public
2026-09-25 03:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-97335",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T14:02:18.270198Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T16:32:28.403Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "LXD",
"platforms": [
"Linux"
],
"product": "LXD",
"repo": "https://github.com/canonical/lxd",
"vendor": "Canonical",
"versions": [
{
"lessThan": "5.0.10",
"status": "affected",
"version": "5.0.0",
"versionType": "semver"
},
{
"lessThan": "5.21.8",
"status": "affected",
"version": "5.21.0",
"versionType": "semver"
},
{
"lessThan": "6.10",
"status": "affected",
"version": "6.0",
"versionType": "semver"
}
]
}
],
"datePublic": "2026-09-25T03:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create custom volumes in a project to copy, and so read, any custom storage volume from any other project on the server, including its snapshots and configuration. The client does this with a crafted request that sets a source volume and source.project but omits source.type."
}
],
"impacts": [
{
"capecId": "CAPEC-122",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-122 Privilege Abuse"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863 Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T13:22:19.371Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-p456-92fx-44xh"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to LXD versions 5.0.10, 5.21.8, 6.10 or later."
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Incorrect authorization in LXD storage volume API allows reading volumes from other projects"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-97335",
"datePublished": "2026-09-28T13:22:19.371Z",
"dateReserved": "2026-09-24T12:15:00.374Z",
"dateUpdated": "2026-09-28T16:32:28.403Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-87799 (GCVE-0-2026-87799)
Vulnerability from nvd – Published: 2026-09-28 13:22 – Updated: 2026-09-29 03:55
VLAI
EPSS
VEX
Title
Arbitrary file write on LXD host via symlink in migration stream
Summary
Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a project, or a malicious migration source server, to write attacker-controlled files to arbitrary paths on the target host as root, leading to full host compromise. The attacker does this with a crafted rsync or btrfs send stream that plants a symlink in the transferred volume, such as rootfs or root.img, and then writes through it.
Severity
9.9 (Critical)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-28 00:00 UTC
CWE
- CWE-59 - Improper link resolution before file access ('link following')
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://github.com/canonical/lxd/security/advisor… | vendor-advisory |
Impacted products
Date Public
2026-09-25 03:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-87799",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T03:55:19.115Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "LXD",
"platforms": [
"Linux"
],
"product": "LXD",
"repo": "https://github.com/canonical/lxd",
"vendor": "Canonical",
"versions": [
{
"lessThan": "4.0.14",
"status": "affected",
"version": "4.0.0",
"versionType": "semver"
},
{
"lessThan": "5.0.10",
"status": "affected",
"version": "5.0.0",
"versionType": "semver"
},
{
"lessThan": "5.21.8",
"status": "affected",
"version": "5.21.0",
"versionType": "semver"
},
{
"lessThan": "6.10",
"status": "affected",
"version": "6.0",
"versionType": "semver"
}
]
}
],
"datePublic": "2026-09-25T03:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a project, or a malicious migration source server, to write attacker-controlled files to arbitrary paths on the target host as root, leading to full host compromise. The attacker does this with a crafted rsync or btrfs send stream that plants a symlink in the transferred volume, such as rootfs or root.img, and then writes through it."
}
],
"impacts": [
{
"capecId": "CAPEC-132",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-132 Symlink Attack"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.9,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-59",
"description": "CWE-59 Improper link resolution before file access (\u0027link following\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T13:22:29.148Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-fmc3-3cpq-6whr"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8, 6.10 or later."
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Arbitrary file write on LXD host via symlink in migration stream"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-87799",
"datePublished": "2026-09-28T13:22:29.148Z",
"dateReserved": "2026-09-09T10:00:46.383Z",
"dateUpdated": "2026-09-29T03:55:19.115Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-87798 (GCVE-0-2026-87798)
Vulnerability from nvd – Published: 2026-09-28 13:22 – Updated: 2026-09-28 16:32
VLAI
EPSS
VEX
Title
LXD client recursive file pull allows directory escape via malicious VM agent
Summary
Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine to write attacker-controlled files or directory trees to arbitrary paths on the client host, with the operator's privileges. The attacker does this by using a modified lxd-agent that returns inconsistent SFTP directory listings and Lstat results.
Severity
5.8 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-28 14:04 UTC
CWE
- CWE-59 - Improper link resolution before file access ('link following')
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://github.com/canonical/lxd/security/advisor… | vendor-advisory |
Impacted products
Date Public
2026-09-25 03:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-87798",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T14:04:47.395647Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T16:32:28.148Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "LXD",
"platforms": [
"Linux"
],
"product": "LXD",
"repo": "https://github.com/canonical/lxd",
"vendor": "Canonical",
"versions": [
{
"lessThan": "4.0.14",
"status": "affected",
"version": "4.0.2",
"versionType": "semver"
},
{
"lessThan": "5.0.10",
"status": "affected",
"version": "5.0.0",
"versionType": "semver"
},
{
"lessThan": "5.21.8",
"status": "affected",
"version": "5.21.0",
"versionType": "semver"
},
{
"lessThan": "6.9",
"status": "affected",
"version": "6.0",
"versionType": "semver"
}
]
}
],
"datePublic": "2026-09-25T03:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine to write attacker-controlled files or directory trees to arbitrary paths on the client host, with the operator\u0027s privileges. The attacker does this by using a modified lxd-agent that returns inconsistent SFTP directory listings and Lstat results."
}
],
"impacts": [
{
"capecId": "CAPEC-132",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-132 Symlink Attack"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.8,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-59",
"description": "CWE-59 Improper link resolution before file access (\u0027link following\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T13:22:36.561Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-mr8v-hx34-hfvf"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8 or later."
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "LXD client recursive file pull allows directory escape via malicious VM agent"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-87798",
"datePublished": "2026-09-28T13:22:36.561Z",
"dateReserved": "2026-09-09T10:00:46.383Z",
"dateUpdated": "2026-09-28T16:32:28.148Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-86335 (GCVE-0-2026-86335)
Vulnerability from nvd – Published: 2026-09-28 13:21 – Updated: 2026-09-28 16:32
VLAI
EPSS
VEX
Title
LXD Cross-Project Private Image Theft via Unsanitized GetImageFromAnyProject Local Reuse
Summary
Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance import requests.
Severity
6.3 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-28 13:49 UTC
CWE
- CWE-862 - Missing Authorization
Assigner
References
5 references
| URL | Tags |
|---|---|
| https://github.com/canonical/lxd/security/advisor… | vendor-advisoryissue-tracking |
| https://github.com/canonical/lxd/pull/19003 | patch |
| https://github.com/canonical/lxd/pull/19002 | patch |
| https://github.com/canonical/lxd/pull/19001 | patch |
| https://github.com/canonical/lxd/pull/18987 | patch |
Impacted products
Date Public
2026-09-25 03:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-86335",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T13:49:04.323716Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T16:32:28.655Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "LXD",
"product": "LXD",
"repo": "https://github.com/canonical/lxd",
"vendor": "Canonical",
"versions": [
{
"lessThan": "5.21.8",
"status": "affected",
"version": "5.21.0",
"versionType": "semver"
},
{
"lessThan": "6.10",
"status": "affected",
"version": "6.0",
"versionType": "semver"
},
{
"lessThan": "5.0.10",
"status": "affected",
"version": "4.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Yuliang Xiao"
}
],
"datePublic": "2026-09-25T03:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Missing Authorization in imageDownload in Canonical LXD before 5.0.10,\u00a05.21.8, and 6.10\u00a0on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance import requests."
}
],
"impacts": [
{
"capecId": "CAPEC-122",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-122 Privilege Abuse"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862 Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T13:21:29.891Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"vendor-advisory",
"issue-tracking"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-j7p3-5g2v-69j8"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd/pull/19003"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd/pull/19002"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd/pull/19001"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd/pull/18987"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to LXD versions 5.0.10, 5.21.8, 6.10 or later."
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "LXD Cross-Project Private Image Theft via Unsanitized GetImageFromAnyProject Local Reuse"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-86335",
"datePublished": "2026-09-28T13:21:29.891Z",
"dateReserved": "2026-09-07T08:01:22.942Z",
"dateUpdated": "2026-09-28T16:32:28.655Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-86334 (GCVE-0-2026-86334)
Vulnerability from nvd – Published: 2026-09-28 13:21 – Updated: 2026-09-28 17:56
VLAI
EPSS
VEX
Title
CLI Path Traversal via Content-Disposition in LXD Image Export/Copy
Summary
Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite arbitrary local files and execute code on the client system via a crafted Content-Disposition header filename parameter during unified image export or copy operations into a local directory target.
Severity
4.2 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-28 17:55 UTC
CWE
- CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://github.com/canonical/lxd/security/advisor… | vendor-advisoryissue-tracking |
| https://github.com/canonical/lxd/pull/18977 | patch |
| https://github.com/canonical/lxd/pull/18976 | patch |
| https://github.com/canonical/lxd/pull/18974 | patch |
| https://github.com/canonical/lxd/pull/18975 | patch |
| https://github.com/canonical/lxd/pull/18940 | patch |
Impacted products
Date Public
2026-09-25 03:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-86334",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T17:55:41.286474Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T17:56:11.126Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-g4cm-f533-78hq"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "LXD",
"platforms": [
"Linux"
],
"product": "LXD",
"repo": "https://github.com/canonical/lxd",
"vendor": "Canonical",
"versions": [
{
"lessThan": "4.0.14",
"status": "affected",
"version": "4.0.2",
"versionType": "semver"
},
{
"lessThan": "5.0.10",
"status": "affected",
"version": "5.0.0",
"versionType": "semver"
},
{
"lessThan": "5.21.8",
"status": "affected",
"version": "5.21.0",
"versionType": "semver"
},
{
"lessThan": "6.10",
"status": "affected",
"version": "6.0",
"versionType": "semver"
}
]
}
],
"datePublic": "2026-09-25T03:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite arbitrary local files and execute code on the client system via a crafted Content-Disposition header filename parameter during unified image export or copy operations into a local directory target."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Path Traversal"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 4.2,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T13:21:15.612Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"vendor-advisory",
"issue-tracking"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-g4cm-f533-78hq"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd/pull/18977"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd/pull/18976"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd/pull/18974"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd/pull/18975"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd/pull/18940"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8, 6.10 or later."
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "CLI Path Traversal via Content-Disposition in LXD Image Export/Copy"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-86334",
"datePublished": "2026-09-28T13:21:15.612Z",
"dateReserved": "2026-09-07T08:01:22.941Z",
"dateUpdated": "2026-09-28T17:56:11.126Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-85526 (GCVE-0-2026-85526)
Vulnerability from nvd – Published: 2026-09-28 13:21 – Updated: 2026-09-29 03:55
VLAI
EPSS
VEX
Title
Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD
Summary
Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvolumes[].path entry in backup/optimized_header.yaml during a btrfs optimized backup import.
Severity
9.9 (Critical)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-28 00:00 UTC
CWE
- CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://github.com/canonical/lxd/security/advisor… | vendor-advisoryissue-tracking |
| https://github.com/canonical/lxd-private/pull/87 | patch |
| https://github.com/canonical/lxd-private/pull/105 | patch |
| https://github.com/canonical/lxd-private/pull/104 | patch |
| https://github.com/canonical/lxd-private/pull/103 | patch |
| https://github.com/canonical/lxd-private/pull/84 | patch |
Impacted products
Date Public
2026-09-25 03:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-85526",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T03:55:18.376Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "LXD",
"platforms": [
"Linux"
],
"product": "LXD",
"repo": "https://github.com/canonical/lxd",
"vendor": "Canonical",
"versions": [
{
"lessThan": "4.0.14",
"status": "affected",
"version": "4.0.0",
"versionType": "semver"
},
{
"lessThan": "5.0.10",
"status": "affected",
"version": "5.0.0",
"versionType": "semver"
},
{
"lessThan": "5.21.8",
"status": "affected",
"version": "5.21.0",
"versionType": "semver"
},
{
"lessThan": "6.10",
"status": "affected",
"version": "6.0",
"versionType": "semver"
}
]
}
],
"datePublic": "2026-09-25T03:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvolumes[].path entry in backup/optimized_header.yaml during a btrfs optimized backup import."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Path Traversal"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.9,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T13:21:40.621Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"vendor-advisory",
"issue-tracking"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-h85r-gjgx-g2rv"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd-private/pull/87"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd-private/pull/105"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd-private/pull/104"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd-private/pull/103"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd-private/pull/84"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8, 6.10 or later."
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-85526",
"datePublished": "2026-09-28T13:21:40.621Z",
"dateReserved": "2026-09-04T08:34:29.842Z",
"dateUpdated": "2026-09-29T03:55:18.376Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-85185 (GCVE-0-2026-85185)
Vulnerability from nvd – Published: 2026-09-28 13:21 – Updated: 2026-09-28 16:32
VLAI
EPSS
VEX
Title
Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root
Summary
Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is btrfs, the client can also place attacker-controlled content at arbitrary host paths, leading to full host compromise. The client does this with a crafted subvolume path containing ../ sequences, sent in either of two ways: in the optimized_header.yaml of an optimized btrfs backup, or in the btrfs migration header sent by a malicious migration source.
Severity
9.6 (Critical)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-28 13:55 UTC
CWE
- CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://github.com/canonical/lxd/security/advisor… | vendor-advisory |
Impacted products
Date Public
2026-09-25 03:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-85185",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T13:55:28.506443Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T16:32:28.529Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "LXD",
"platforms": [
"Linux"
],
"product": "LXD",
"repo": "https://github.com/canonical/lxd",
"vendor": "Canonical",
"versions": [
{
"lessThan": "4.0.14",
"status": "affected",
"version": "4.0.2",
"versionType": "semver"
},
{
"lessThan": "5.0.10",
"status": "affected",
"version": "5.0.0",
"versionType": "semver"
},
{
"lessThan": "5.21.8",
"status": "affected",
"version": "5.21.0",
"versionType": "semver"
},
{
"lessThan": "6.10",
"status": "affected",
"version": "6.0",
"versionType": "semver"
}
]
}
],
"datePublic": "2026-09-25T03:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is btrfs, the client can also place attacker-controlled content at arbitrary host paths, leading to full host compromise. The client does this with a crafted subvolume path containing ../ sequences, sent in either of two ways: in the optimized_header.yaml of an optimized btrfs backup, or in the btrfs migration header sent by a malicious migration source."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Path Traversal"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.6,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T13:21:51.596Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-27q7-qwhm-c34p"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8, 6.10 or later."
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-85185",
"datePublished": "2026-09-28T13:21:51.596Z",
"dateReserved": "2026-09-03T11:46:34.569Z",
"dateUpdated": "2026-09-28T16:32:28.529Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-66897 (GCVE-0-2026-66897)
Vulnerability from nvd – Published: 2026-08-24 09:08 – Updated: 2026-08-25 03:55
VLAI
EPSS
VEX
Title
Instance template path traversal allows arbitrary host file write as root
Summary
A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in metadata.yaml, LXD validates the path against a confined os.Root directory handle but subsequently opens and creates the file using os.Create with an unconfined string path. This discrepancy between path resolution checks and file creation allows an attacker to escape directory confinement, overwrite root-owned host files, and achieve host root code execution.
Severity
9.9 (Critical)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-24 00:00 UTC
CWE
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://github.com/canonical/lxd/security/advisor… | vdb-entryvendor-advisory |
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-66897",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-24T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T03:55:49.930Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "LXD",
"platforms": [
"Linux"
],
"product": "LXD",
"repo": "https://github.com/canonical/lxd",
"vendor": "Canonical",
"versions": [
{
"lessThan": "4.0.13",
"status": "affected",
"version": "4.0.0",
"versionType": "semver"
},
{
"lessThan": "5.0.9",
"status": "affected",
"version": "5.0.0",
"versionType": "semver"
},
{
"lessThan": "5.21.7",
"status": "affected",
"version": "5.21.0",
"versionType": "semver"
},
{
"lessThan": "6.10",
"status": "affected",
"version": "6.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A path traversal vulnerability in LXD\u0027s instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in metadata.yaml, LXD validates the path against a confined os.Root directory handle but subsequently opens and creates the file using os.Create with an unconfined string path. This discrepancy between path resolution checks and file creation allows an attacker to escape directory confinement, overwrite root-owned host files, and achieve host root code execution."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "Path Traversal"
}
]
},
{
"capecId": "CAPEC-153",
"descriptions": [
{
"lang": "en",
"value": "Input Data Manipulation"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.9,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
},
{
"cweId": "CWE-23",
"description": "CWE-23: Relative Path Traversal",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-24T09:08:04.188Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"vdb-entry",
"vendor-advisory"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-q39m-8fx9-42fv"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to LXD versions 4.0.13, 5.0.9, 5.21.7, 6.10 or later."
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Instance template path traversal allows arbitrary host file write as root"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-66897",
"datePublished": "2026-08-24T09:08:04.188Z",
"dateReserved": "2026-07-28T07:41:26.310Z",
"dateUpdated": "2026-08-25T03:55:49.930Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-77113 (GCVE-0-2026-77113)
Vulnerability from nvd – Published: 2026-08-20 22:32 – Updated: 2026-08-21 20:08
VLAI
EPSS
VEX
Title
Path Traversal Vulnerability in apport-unpack
Summary
Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in crash report files.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-21 19:50 UTC
CWE
- CWE-23 - Relative path traversal
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://launchpad.net/bugs/2161697 | issue-trackingvendor-advisory |
| https://github.com/canonical/apport/pull/646 | patch |
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-77113",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-21T19:50:19.847915Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-21T20:08:37.866Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "apport-unpack",
"platforms": [
"Linux"
],
"product": "Apport",
"programFiles": [
"problem_report.py"
],
"repo": "https://github.com/canonical/apport",
"vendor": "Canonical",
"versions": [
{
"lessThan": "2.36.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "2.34.2",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "2.28.4",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:canonical:apport:*:*:linux:*:*:*:*:*",
"versionEndExcluding": "2.36.0",
"versionStartIncluding": "0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:canonical:apport:*:*:linux:*:*:*:*:*",
"versionEndExcluding": "2.34.2",
"versionStartIncluding": "0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:canonical:apport:*:*:linux:*:*:*:*:*",
"versionEndExcluding": "2.28.4",
"versionStartIncluding": "0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Sakib Sarkar (0xROI)"
}
],
"descriptions": [
{
"lang": "en",
"value": "Path traversal in apport-unpack in Canonical Apport before\u00a02.36.0,\u00a02.34.2, and\u00a02.28.4\u00a0on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in crash report files."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Path Traversal"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "LOCAL",
"baseScore": 6.7,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "ACTIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-23",
"description": "CWE-23 Relative path traversal",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-20T22:32:51.447Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"issue-tracking",
"vendor-advisory"
],
"url": "https://launchpad.net/bugs/2161697"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/apport/pull/646"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Path Traversal Vulnerability in apport-unpack",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-77113",
"datePublished": "2026-08-20T22:32:51.447Z",
"dateReserved": "2026-08-20T11:53:23.292Z",
"dateUpdated": "2026-08-21T20:08:37.866Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-61898 (GCVE-0-2026-61898)
Vulnerability from nvd – Published: 2026-08-20 14:32 – Updated: 2026-08-26 19:50
VLAI
EPSS
VEX
Title
accountsservice: shell injection via attacker-controlled ~/.pam_environment in Ubuntu language helper scripts
Summary
The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject a sed 'e' flag and arbitrary shell commands that execute with the privileges of the AccountsService helper process (real UID 0) via the SetLanguage D-Bus method.
Severity
7.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-26 19:43 UTC
CWE
- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://bugs.launchpad.net/ubuntu/+source/account… | issue-tracking |
| https://ubuntu.com/security/CVE-2026-61898 | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Canonical | accountsservice |
Affected:
22.07.5-2ubuntu1 , < 22.07.5-2ubuntu1.6
(dpkg)
Affected: 23.13.9-2ubuntu6 , < 23.13.9-2ubuntu6.1 (dpkg) Affected: 23.13.9-8ubuntu5 , < 23.13.9-8ubuntu5.2 (dpkg) Affected: 23.13.9-8ubuntu6 , < 23.13.9-8ubuntu7 (dpkg) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-61898",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-26T19:43:44.504304Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-26T19:50:34.552Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "accountsservice",
"platforms": [
"Ubuntu 14.04 LTS",
"Ubuntu 16.04 LTS",
"Ubuntu 18.04 LTS",
"Ubuntu 20.04 LTS",
"Ubuntu 22.04 LTS",
"Ubuntu 24.04 LTS",
"Ubuntu 26.04 LTS",
"Ubuntu 26.10"
],
"product": "accountsservice",
"vendor": "Canonical",
"versions": [
{
"lessThan": "22.07.5-2ubuntu1.6",
"status": "affected",
"version": "22.07.5-2ubuntu1",
"versionType": "dpkg"
},
{
"lessThan": "23.13.9-2ubuntu6.1",
"status": "affected",
"version": "23.13.9-2ubuntu6",
"versionType": "dpkg"
},
{
"lessThan": "23.13.9-8ubuntu5.2",
"status": "affected",
"version": "23.13.9-8ubuntu5",
"versionType": "dpkg"
},
{
"lessThan": "23.13.9-8ubuntu7",
"status": "affected",
"version": "23.13.9-8ubuntu6",
"versionType": "dpkg"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Deutsche Telekom Security GmbH Red Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject a sed \u0027e\u0027 flag and arbitrary shell commands that execute with the privileges of the AccountsService helper process (real UID 0) via the SetLanguage D-Bus method."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-20T14:32:59.924Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"name": "Launchpad Bug #2157985",
"tags": [
"issue-tracking"
],
"url": "https://bugs.launchpad.net/ubuntu/+source/accountsservice/+bug/2157985"
},
{
"name": "Ubuntu CVE Tracker",
"tags": [
"vendor-advisory"
],
"url": "https://ubuntu.com/security/CVE-2026-61898"
}
],
"title": "accountsservice: shell injection via attacker-controlled ~/.pam_environment in Ubuntu language helper scripts"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-61898",
"datePublished": "2026-08-20T14:32:59.924Z",
"dateReserved": "2026-07-11T18:43:51.251Z",
"dateUpdated": "2026-08-26T19:50:34.552Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-61897 (GCVE-0-2026-61897)
Vulnerability from nvd – Published: 2026-08-20 14:32 – Updated: 2026-08-26 19:50
VLAI
EPSS
VEX
Title
accountsservice: incomplete privilege drop when running Ubuntu-specific language helper scripts
Summary
An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to root, enabling local privilege escalation.
Severity
7.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-26 19:43 UTC
CWE
- CWE-273 - Improper Check for Dropped Privileges
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://bugs.launchpad.net/ubuntu/+source/account… | issue-tracking |
| https://ubuntu.com/security/CVE-2026-61897 | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Canonical | accountsservice |
Affected:
22.07.5-2ubuntu1 , < 22.07.5-2ubuntu1.6
(dpkg)
Affected: 23.13.9-2ubuntu6 , < 23.13.9-2ubuntu6.1 (dpkg) Affected: 23.13.9-8ubuntu5 , < 23.13.9-8ubuntu5.2 (dpkg) Affected: 23.13.9-8ubuntu6 , < 23.13.9-8ubuntu7 (dpkg) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-61897",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-26T19:43:37.600246Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-26T19:50:49.398Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "accountsservice",
"platforms": [
"Ubuntu 14.04 LTS",
"Ubuntu 16.04 LTS",
"Ubuntu 18.04 LTS",
"Ubuntu 20.04 LTS",
"Ubuntu 22.04 LTS",
"Ubuntu 24.04 LTS",
"Ubuntu 26.04 LTS",
"Ubuntu 26.10"
],
"product": "accountsservice",
"vendor": "Canonical",
"versions": [
{
"lessThan": "22.07.5-2ubuntu1.6",
"status": "affected",
"version": "22.07.5-2ubuntu1",
"versionType": "dpkg"
},
{
"lessThan": "23.13.9-2ubuntu6.1",
"status": "affected",
"version": "23.13.9-2ubuntu6",
"versionType": "dpkg"
},
{
"lessThan": "23.13.9-8ubuntu5.2",
"status": "affected",
"version": "23.13.9-8ubuntu5",
"versionType": "dpkg"
},
{
"lessThan": "23.13.9-8ubuntu7",
"status": "affected",
"version": "23.13.9-8ubuntu6",
"versionType": "dpkg"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Deutsche Telekom Security GmbH Red Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to root, enabling local privilege escalation."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-273",
"description": "CWE-273: Improper Check for Dropped Privileges",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-20T14:32:53.827Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"name": "Launchpad Bug #2157985",
"tags": [
"issue-tracking"
],
"url": "https://bugs.launchpad.net/ubuntu/+source/accountsservice/+bug/2157985"
},
{
"name": "Ubuntu CVE Tracker",
"tags": [
"vendor-advisory"
],
"url": "https://ubuntu.com/security/CVE-2026-61897"
}
],
"title": "accountsservice: incomplete privilege drop when running Ubuntu-specific language helper scripts"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-61897",
"datePublished": "2026-08-20T14:32:53.827Z",
"dateReserved": "2026-07-11T18:43:51.251Z",
"dateUpdated": "2026-08-26T19:50:49.398Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-66898 (GCVE-0-2026-66898)
Vulnerability from nvd – Published: 2026-08-12 20:07 – Updated: 2026-08-13 13:40
VLAI
EPSS
VEX
Title
Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE
Summary
A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside the designated restore directory.
Severity
9.9 (Critical)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-13 13:40 UTC
CWE
- CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://github.com/canonical/lxd/security/advisor… | vdb-entryvendor-advisory |
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-66898",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-13T13:40:15.405663Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-13T13:40:18.070Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-m857-c7gc-c984"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "LXD",
"platforms": [
"Linux"
],
"product": "LXD",
"repo": "https://github.com/canonical/lxd",
"vendor": "Canonical",
"versions": [
{
"lessThan": "4.0.12",
"status": "affected",
"version": "4.0.0",
"versionType": "semver"
},
{
"lessThan": "5.0.4",
"status": "affected",
"version": "5.0.0",
"versionType": "semver"
},
{
"lessThan": "5.21.2",
"status": "affected",
"version": "5.21.0",
"versionType": "semver"
},
{
"lessThan": "6.1",
"status": "affected",
"version": "6.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside the designated restore directory."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "Path Traversal"
}
]
},
{
"capecId": "CAPEC-153",
"descriptions": [
{
"lang": "en",
"value": "Input Data Manipulation"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.9,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-12T20:07:32.889Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"vdb-entry",
"vendor-advisory"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-m857-c7gc-c984"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to LXD version 4.0.12 or later, 5.0.4 or later, or 5.12.2 or later, or 6.0 or later."
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-66898",
"datePublished": "2026-08-12T20:07:32.889Z",
"dateReserved": "2026-07-28T07:41:26.311Z",
"dateUpdated": "2026-08-13T13:40:18.070Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-16033 (GCVE-0-2026-16033)
Vulnerability from nvd – Published: 2026-08-12 20:11 – Updated: 2026-08-13 12:46
VLAI
EPSS
VEX
Title
Arbitrary file read+write on host via templates/ symlink in malicious image
Summary
A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the instance templates directory (specifically affecting virtual machine / QEMU driver execution paths). An attacker can exploit this flaw by providing a crafted image archive with malicious template directives containing path traversal sequences, causing LXD to access or write files outside the intended template directory on the host system.
Severity
8.5 (High)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-13 12:45 UTC
CWE
- CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://github.com/canonical/lxd/security/advisor… | vdb-entryvendor-advisory |
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-16033",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-13T12:45:51.004847Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-13T12:46:08.117Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-9hcm-hxh5-7xxh"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "LXD",
"platforms": [
"Linux"
],
"product": "LXD",
"repo": "https://github.com/canonical/lxd",
"vendor": "Canonical",
"versions": [
{
"lessThan": "4.0.12",
"status": "affected",
"version": "4.0.0",
"versionType": "semver"
},
{
"lessThan": "5.0.8",
"status": "affected",
"version": "5.0.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the instance templates directory (specifically affecting virtual machine / QEMU driver execution paths). An attacker can exploit this flaw by providing a crafted image archive with malicious template directives containing path traversal sequences, causing LXD to access or write files outside the intended template directory on the host system."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "Path Traversal"
}
]
},
{
"capecId": "CAPEC-153",
"descriptions": [
{
"lang": "en",
"value": "Input Data Manipulation"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-12T20:11:08.781Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"vdb-entry",
"vendor-advisory"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-9hcm-hxh5-7xxh"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to LXD version 4.0.12 or later, or 5.0.8 or later."
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Arbitrary file read+write on host via templates/ symlink in malicious image"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-16033",
"datePublished": "2026-08-12T20:11:08.781Z",
"dateReserved": "2026-07-17T08:44:31.450Z",
"dateUpdated": "2026-08-13T12:46:08.117Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63300 (GCVE-0-2026-63300)
Vulnerability from nvd – Published: 2026-08-12 19:09 – Updated: 2026-08-13 13:19
VLAI
EPSS
VEX
Title
Cross-project instance move bypasses all project restrictions allowing host command execution
Summary
An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security restrictions. When migrating an instance between projects, LXD fails to validate the instance's configuration against the target project's enforced restrictions (such as restricted.containers.lowlevel, restricted.devices.*, and restricted.networks.access). An attacker can exploit this by creating a disallowed or high-privilege instance in an unrestricted project and subsequently moving it into the restricted project.
Severity
9.9 (Critical)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-13 03:55 UTC
CWE
- CWE-862 - Missing Authorization
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/canonical/lxd/security/advisor… | vdb-entryvendor-advisory |
| https://github.com/canonical/lxd/pull/18651 | patch |
| https://github.com/canonical/lxd/pull/18605 | patch |
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-63300",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-13T03:55:57.925616Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-13T13:19:51.113Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "LXD",
"platforms": [
"Linux"
],
"product": "LXD",
"repo": "https://github.com/canonical/lxd",
"vendor": "Canonical",
"versions": [
{
"lessThan": "5.0.8",
"status": "affected",
"version": "5.0.0",
"versionType": "semver"
},
{
"lessThan": "5.21.6",
"status": "affected",
"version": "5.21.0",
"versionType": "semver"
},
{
"lessThan": "6.10",
"status": "affected",
"version": "6.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security restrictions. When migrating an instance between projects, LXD fails to validate the instance\u0027s configuration against the target project\u0027s enforced restrictions (such as restricted.containers.lowlevel, restricted.devices.*, and restricted.networks.access). An attacker can exploit this by creating a disallowed or high-privilege instance in an unrestricted project and subsequently moving it into the restricted project."
}
],
"impacts": [
{
"capecId": "CAPEC-180",
"descriptions": [
{
"lang": "en",
"value": "Exploiting Incorrectly Configured Access Control Security Levels"
}
]
},
{
"capecId": "CAPEC-122",
"descriptions": [
{
"lang": "en",
"value": "Privilege Abuse"
}
]
},
{
"capecId": "CAPEC-233",
"descriptions": [
{
"lang": "en",
"value": "Privilege Escalation"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.9,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862 Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-12T19:09:04.445Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"vdb-entry",
"vendor-advisory"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-5g5r-wh97-qcq2"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd/pull/18651"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd/pull/18605"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to LXD version 5.0.8 or later, 5.21.6 or later, or 6.10 or later."
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Cross-project instance move bypasses all project restrictions allowing host command execution"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-63300",
"datePublished": "2026-08-12T19:09:04.445Z",
"dateReserved": "2026-07-16T10:01:05.653Z",
"dateUpdated": "2026-08-13T13:19:51.113Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63299 (GCVE-0-2026-63299)
Vulnerability from nvd – Published: 2026-08-12 19:17 – Updated: 2026-08-12 19:26
VLAI
EPSS
VEX
Title
Storage volume cross-project move and snapshot restore bypass project disk limits
Summary
An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations: the storagePoolVolumeTypePostMove function omits the limits.AllowVolumeCreation check before moving a volume across projects, and volume snapshot restore operations skip the AllowVolumeUpdate check when the configuration is nil (Config == nil). An attacker can exploit these flaws to allocate storage resources that exceed the administrative limits configured for a project.
Severity
8.5 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-12 19:26 UTC
CWE
- CWE-770 - Allocation of Resources Without Limits or Throttling
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://github.com/canonical/lxd/security/advisor… | vdb-entryvendor-advisory |
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-63299",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-12T19:26:19.187565Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-12T19:26:28.110Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "LXD",
"platforms": [
"Linux"
],
"product": "LXD",
"repo": "https://github.com/canonical/lxd",
"vendor": "Canonical",
"versions": [
{
"lessThan": "5.0.8",
"status": "affected",
"version": "5.0.0",
"versionType": "semver"
},
{
"lessThan": "5.21.6",
"status": "affected",
"version": "5.21.0",
"versionType": "semver"
},
{
"lessThan": "6.10",
"status": "affected",
"version": "6.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations: the storagePoolVolumeTypePostMove function omits the limits.AllowVolumeCreation check before moving a volume across projects, and volume snapshot restore operations skip the AllowVolumeUpdate check when the configuration is nil (Config == nil). An attacker can exploit these flaws to allocate storage resources that exceed the administrative limits configured for a project."
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "Accessing Functionality Not Properly Constrained by ACLs"
}
]
},
{
"capecId": "CAPEC-122",
"descriptions": [
{
"lang": "en",
"value": "Privilege Abuse"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-770",
"description": "CWE-770 Allocation of Resources Without Limits or Throttling",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-12T19:17:07.418Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"vdb-entry",
"vendor-advisory"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-5h78-p252-989h"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to LXD version 5.0.8 or later, 5.21.6 or later, or 6.10 or later."
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Storage volume cross-project move and snapshot restore bypass project disk limits"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-63299",
"datePublished": "2026-08-12T19:17:07.418Z",
"dateReserved": "2026-07-16T10:01:05.653Z",
"dateUpdated": "2026-08-12T19:26:28.110Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63298 (GCVE-0-2026-63298)
Vulnerability from nvd – Published: 2026-08-12 19:22 – Updated: 2026-08-13 14:33
VLAI
EPSS
VEX
Title
LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration
Summary
An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or 'nvidia.require.*' configuration values, an attacker can manipulate the generated lxc.conf file. This flaw enables the attacker to execute arbitrary code on the host system with the privileges of the LXD daemon.
Severity
8.7 (High)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-13 14:33 UTC
CWE
- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://github.com/canonical/lxd/security/advisor… | vdb-entryvendor-advisory |
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-63298",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-13T14:33:35.469940Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-13T14:33:57.467Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-vfh7-q59q-54v2"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "LXD",
"platforms": [
"Linux"
],
"product": "LXD",
"repo": "https://github.com/canonical/lxd",
"vendor": "Canonical",
"versions": [
{
"lessThan": "5.0.8",
"status": "affected",
"version": "5.0.0",
"versionType": "semver"
},
{
"lessThan": "5.21.6",
"status": "affected",
"version": "5.21.0",
"versionType": "semver"
},
{
"lessThan": "4.0.12",
"status": "affected",
"version": "4.0.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An improper neutralization of special elements vulnerability in LXD\u0027s NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the \u0027nvidia.driver.capabilities\u0027 or \u0027nvidia.require.*\u0027 configuration values, an attacker can manipulate the generated lxc.conf file. This flaw enables the attacker to execute arbitrary code on the host system with the privileges of the LXD daemon."
}
],
"impacts": [
{
"capecId": "CAPEC-81",
"descriptions": [
{
"lang": "en",
"value": "Input Data Manipulation"
}
]
},
{
"capecId": "CAPEC-233",
"descriptions": [
{
"lang": "en",
"value": "Privilege Escalation"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-12T19:22:07.286Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"vdb-entry",
"vendor-advisory"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-vfh7-q59q-54v2"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to LXD version 4.0.12 or later, 5.0.8 or later, or 5.12.6 or later."
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-63298",
"datePublished": "2026-08-12T19:22:07.286Z",
"dateReserved": "2026-07-16T09:49:29.911Z",
"dateUpdated": "2026-08-13T14:33:57.467Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63297 (GCVE-0-2026-63297)
Vulnerability from nvd – Published: 2026-08-12 19:25 – Updated: 2026-08-13 14:29
VLAI
EPSS
VEX
Title
Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge
Summary
An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a target project, LXD performs restriction checks before configuration merging is complete, creating a time-of-check to time-of-use (TOCTOU) condition. An attacker can exploit this flaw to copy instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.
Severity
9.9 (Critical)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-13 14:28 UTC
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://github.com/canonical/lxd/security/advisor… | vdb-entryvendor-advisory |
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-63297",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-13T14:28:52.383092Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-13T14:29:39.772Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-v989-qw7w-xvg4"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "LXD",
"platforms": [
"Linux"
],
"product": "LXD",
"repo": "https://github.com/canonical/lxd",
"vendor": "Canonical",
"versions": [
{
"lessThan": "5.0.8",
"status": "affected",
"version": "5.0.0",
"versionType": "semver"
},
{
"lessThan": "5.21.6",
"status": "affected",
"version": "5.21.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a target project, LXD performs restriction checks before configuration merging is complete, creating a time-of-check to time-of-use (TOCTOU) condition. An attacker can exploit this flaw to copy instances with disallowed high-privilege configurations into restricted projects, bypassing security controls."
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "Accessing Functionality Not Properly Constrained by ACLs"
}
]
},
{
"capecId": "CAPEC-122",
"descriptions": [
{
"lang": "en",
"value": "Privilege Abuse"
}
]
},
{
"capecId": "CAPEC-233",
"descriptions": [
{
"lang": "en",
"value": "Privilege Escalation"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.9,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-367",
"description": "CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition",
"lang": "en",
"type": "CWE"
},
{
"cweId": "CWE-863",
"description": "CWE-863 Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-12T19:25:24.420Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"vdb-entry",
"vendor-advisory"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-v989-qw7w-xvg4"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to LXD version 5.0.8 or later, or 5.12.6 or later."
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-63297",
"datePublished": "2026-08-12T19:25:24.420Z",
"dateReserved": "2026-07-16T09:49:29.911Z",
"dateUpdated": "2026-08-13T14:29:39.772Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102371 (GCVE-0-2026-102371)
Vulnerability from cvelistv5 – Published: 2026-09-29 14:11 – Updated: 2026-09-30 15:28
VLAI
EPSS
VEX
Title
wsl-pro-service: Ubuntu Pro token exposed via process command-line arguments
Summary
In wsl-pro-service before 0.1.19ubuntu3, the service component which runs as root inside each WSL instance attaches the instance to Ubuntu Pro by executing the pro client with the Ubuntu Pro token passed as a command-line argument (pro attach <token>). On systems where /proc is mounted without process-hiding mitigations (such as hidepid), which is the default in WSL, an unprivileged local user or process in the same WSL instance can read the token from /proc/<pid>/cmdline while the attach process is running. The leaked token could then be used to attach other machines to the victim's Ubuntu Pro subscription and gain unauthorized access to Ubuntu Pro services.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 15:17 UTC
CWE
- CWE-214 - Invocation of process using visible sensitive information
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/canonical/ubuntu-pro-for-wsl/p… | patch |
| https://github.com/canonical/ubuntu-pro-for-wsl/c… | patch |
| https://ubuntu.com/security/CVE-2026-102371 | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Canonical | Ubuntu Pro for WSL |
Affected:
0.1.1 , < 0.1.19ubuntu2
(ubuntu-resolute)
Affected: 0.1.1 , < 0.1.18~24.04.3 (ubuntu-noble) Affected: 0.1.1 , < 0.1.18~22.04.2 (ubuntu-jammy) Affected: 0.1.1 , < 0.1.18~20.04.2 (ubuntu-focal) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102371",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T15:17:31.871369Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T15:28:19.783Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "wsl-pro-service",
"platforms": [
"Linux"
],
"product": "Ubuntu Pro for WSL",
"repo": "https://github.com/canonical/ubuntu-pro-for-wsl",
"vendor": "Canonical",
"versions": [
{
"lessThan": "0.1.19ubuntu2",
"status": "affected",
"version": "0.1.1",
"versionType": "ubuntu-resolute"
},
{
"lessThan": "0.1.18~24.04.3",
"status": "affected",
"version": "0.1.1",
"versionType": "ubuntu-noble"
},
{
"lessThan": "0.1.18~22.04.2",
"status": "affected",
"version": "0.1.1",
"versionType": "ubuntu-jammy"
},
{
"lessThan": "0.1.18~20.04.2",
"status": "affected",
"version": "0.1.1",
"versionType": "ubuntu-focal"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Darshan U"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Carlos Nihelton"
}
],
"descriptions": [
{
"lang": "en",
"value": "In wsl-pro-service before 0.1.19ubuntu3, the service component which runs as root inside each WSL instance attaches the instance to Ubuntu Pro by executing the pro client with the Ubuntu Pro token passed as a command-line argument (pro attach \u003ctoken\u003e). On systems where /proc is mounted without process-hiding mitigations (such as hidepid), which is the default in WSL, an unprivileged local user or process in the same WSL instance can read the token from /proc/\u003cpid\u003e/cmdline while the attach process is running. The leaked token could then be used to attach other machines to the victim\u0027s Ubuntu Pro subscription and gain unauthorized access to Ubuntu Pro services."
}
],
"impacts": [
{
"capecId": "CAPEC-639",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-639 Probe System Files"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "LOCAL",
"baseScore": 5.7,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-214",
"description": "CWE-214 Invocation of process using visible sensitive information",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T14:11:19.350Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/ubuntu-pro-for-wsl/pull/1816"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/ubuntu-pro-for-wsl/commit/11c164a37b806bcf2a2304beb0d65e406739778b"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://ubuntu.com/security/CVE-2026-102371"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "wsl-pro-service: Ubuntu Pro token exposed via process command-line arguments",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-102371",
"datePublished": "2026-09-29T14:11:19.350Z",
"dateReserved": "2026-09-28T23:44:11.787Z",
"dateUpdated": "2026-09-30T15:28:19.783Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-87798 (GCVE-0-2026-87798)
Vulnerability from cvelistv5 – Published: 2026-09-28 13:22 – Updated: 2026-09-28 16:32
VLAI
EPSS
VEX
Title
LXD client recursive file pull allows directory escape via malicious VM agent
Summary
Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine to write attacker-controlled files or directory trees to arbitrary paths on the client host, with the operator's privileges. The attacker does this by using a modified lxd-agent that returns inconsistent SFTP directory listings and Lstat results.
Severity
5.8 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-28 14:04 UTC
CWE
- CWE-59 - Improper link resolution before file access ('link following')
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://github.com/canonical/lxd/security/advisor… | vendor-advisory |
Impacted products
Date Public
2026-09-25 03:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-87798",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T14:04:47.395647Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T16:32:28.148Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "LXD",
"platforms": [
"Linux"
],
"product": "LXD",
"repo": "https://github.com/canonical/lxd",
"vendor": "Canonical",
"versions": [
{
"lessThan": "4.0.14",
"status": "affected",
"version": "4.0.2",
"versionType": "semver"
},
{
"lessThan": "5.0.10",
"status": "affected",
"version": "5.0.0",
"versionType": "semver"
},
{
"lessThan": "5.21.8",
"status": "affected",
"version": "5.21.0",
"versionType": "semver"
},
{
"lessThan": "6.9",
"status": "affected",
"version": "6.0",
"versionType": "semver"
}
]
}
],
"datePublic": "2026-09-25T03:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine to write attacker-controlled files or directory trees to arbitrary paths on the client host, with the operator\u0027s privileges. The attacker does this by using a modified lxd-agent that returns inconsistent SFTP directory listings and Lstat results."
}
],
"impacts": [
{
"capecId": "CAPEC-132",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-132 Symlink Attack"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.8,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-59",
"description": "CWE-59 Improper link resolution before file access (\u0027link following\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T13:22:36.561Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-mr8v-hx34-hfvf"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8 or later."
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "LXD client recursive file pull allows directory escape via malicious VM agent"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-87798",
"datePublished": "2026-09-28T13:22:36.561Z",
"dateReserved": "2026-09-09T10:00:46.383Z",
"dateUpdated": "2026-09-28T16:32:28.148Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-87799 (GCVE-0-2026-87799)
Vulnerability from cvelistv5 – Published: 2026-09-28 13:22 – Updated: 2026-09-29 03:55
VLAI
EPSS
VEX
Title
Arbitrary file write on LXD host via symlink in migration stream
Summary
Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a project, or a malicious migration source server, to write attacker-controlled files to arbitrary paths on the target host as root, leading to full host compromise. The attacker does this with a crafted rsync or btrfs send stream that plants a symlink in the transferred volume, such as rootfs or root.img, and then writes through it.
Severity
9.9 (Critical)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-28 00:00 UTC
CWE
- CWE-59 - Improper link resolution before file access ('link following')
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://github.com/canonical/lxd/security/advisor… | vendor-advisory |
Impacted products
Date Public
2026-09-25 03:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-87799",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T03:55:19.115Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "LXD",
"platforms": [
"Linux"
],
"product": "LXD",
"repo": "https://github.com/canonical/lxd",
"vendor": "Canonical",
"versions": [
{
"lessThan": "4.0.14",
"status": "affected",
"version": "4.0.0",
"versionType": "semver"
},
{
"lessThan": "5.0.10",
"status": "affected",
"version": "5.0.0",
"versionType": "semver"
},
{
"lessThan": "5.21.8",
"status": "affected",
"version": "5.21.0",
"versionType": "semver"
},
{
"lessThan": "6.10",
"status": "affected",
"version": "6.0",
"versionType": "semver"
}
]
}
],
"datePublic": "2026-09-25T03:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a project, or a malicious migration source server, to write attacker-controlled files to arbitrary paths on the target host as root, leading to full host compromise. The attacker does this with a crafted rsync or btrfs send stream that plants a symlink in the transferred volume, such as rootfs or root.img, and then writes through it."
}
],
"impacts": [
{
"capecId": "CAPEC-132",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-132 Symlink Attack"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.9,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-59",
"description": "CWE-59 Improper link resolution before file access (\u0027link following\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T13:22:29.148Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-fmc3-3cpq-6whr"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8, 6.10 or later."
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Arbitrary file write on LXD host via symlink in migration stream"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-87799",
"datePublished": "2026-09-28T13:22:29.148Z",
"dateReserved": "2026-09-09T10:00:46.383Z",
"dateUpdated": "2026-09-29T03:55:19.115Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-97335 (GCVE-0-2026-97335)
Vulnerability from cvelistv5 – Published: 2026-09-28 13:22 – Updated: 2026-09-28 16:32
VLAI
EPSS
VEX
Title
Incorrect authorization in LXD storage volume API allows reading volumes from other projects
Summary
Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create custom volumes in a project to copy, and so read, any custom storage volume from any other project on the server, including its snapshots and configuration. The client does this with a crafted request that sets a source volume and source.project but omits source.type.
Severity
7.7 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-28 14:02 UTC
CWE
- CWE-863 - Incorrect Authorization
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://github.com/canonical/lxd/security/advisor… | vendor-advisory |
Impacted products
Date Public
2026-09-25 03:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-97335",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T14:02:18.270198Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T16:32:28.403Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "LXD",
"platforms": [
"Linux"
],
"product": "LXD",
"repo": "https://github.com/canonical/lxd",
"vendor": "Canonical",
"versions": [
{
"lessThan": "5.0.10",
"status": "affected",
"version": "5.0.0",
"versionType": "semver"
},
{
"lessThan": "5.21.8",
"status": "affected",
"version": "5.21.0",
"versionType": "semver"
},
{
"lessThan": "6.10",
"status": "affected",
"version": "6.0",
"versionType": "semver"
}
]
}
],
"datePublic": "2026-09-25T03:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create custom volumes in a project to copy, and so read, any custom storage volume from any other project on the server, including its snapshots and configuration. The client does this with a crafted request that sets a source volume and source.project but omits source.type."
}
],
"impacts": [
{
"capecId": "CAPEC-122",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-122 Privilege Abuse"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863 Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T13:22:19.371Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-p456-92fx-44xh"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to LXD versions 5.0.10, 5.21.8, 6.10 or later."
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Incorrect authorization in LXD storage volume API allows reading volumes from other projects"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-97335",
"datePublished": "2026-09-28T13:22:19.371Z",
"dateReserved": "2026-09-24T12:15:00.374Z",
"dateUpdated": "2026-09-28T16:32:28.403Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-85185 (GCVE-0-2026-85185)
Vulnerability from cvelistv5 – Published: 2026-09-28 13:21 – Updated: 2026-09-28 16:32
VLAI
EPSS
VEX
Title
Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root
Summary
Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is btrfs, the client can also place attacker-controlled content at arbitrary host paths, leading to full host compromise. The client does this with a crafted subvolume path containing ../ sequences, sent in either of two ways: in the optimized_header.yaml of an optimized btrfs backup, or in the btrfs migration header sent by a malicious migration source.
Severity
9.6 (Critical)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-28 13:55 UTC
CWE
- CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://github.com/canonical/lxd/security/advisor… | vendor-advisory |
Impacted products
Date Public
2026-09-25 03:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-85185",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T13:55:28.506443Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T16:32:28.529Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "LXD",
"platforms": [
"Linux"
],
"product": "LXD",
"repo": "https://github.com/canonical/lxd",
"vendor": "Canonical",
"versions": [
{
"lessThan": "4.0.14",
"status": "affected",
"version": "4.0.2",
"versionType": "semver"
},
{
"lessThan": "5.0.10",
"status": "affected",
"version": "5.0.0",
"versionType": "semver"
},
{
"lessThan": "5.21.8",
"status": "affected",
"version": "5.21.0",
"versionType": "semver"
},
{
"lessThan": "6.10",
"status": "affected",
"version": "6.0",
"versionType": "semver"
}
]
}
],
"datePublic": "2026-09-25T03:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is btrfs, the client can also place attacker-controlled content at arbitrary host paths, leading to full host compromise. The client does this with a crafted subvolume path containing ../ sequences, sent in either of two ways: in the optimized_header.yaml of an optimized btrfs backup, or in the btrfs migration header sent by a malicious migration source."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Path Traversal"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.6,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T13:21:51.596Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-27q7-qwhm-c34p"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8, 6.10 or later."
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-85185",
"datePublished": "2026-09-28T13:21:51.596Z",
"dateReserved": "2026-09-03T11:46:34.569Z",
"dateUpdated": "2026-09-28T16:32:28.529Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-85526 (GCVE-0-2026-85526)
Vulnerability from cvelistv5 – Published: 2026-09-28 13:21 – Updated: 2026-09-29 03:55
VLAI
EPSS
VEX
Title
Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD
Summary
Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvolumes[].path entry in backup/optimized_header.yaml during a btrfs optimized backup import.
Severity
9.9 (Critical)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-28 00:00 UTC
CWE
- CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://github.com/canonical/lxd/security/advisor… | vendor-advisoryissue-tracking |
| https://github.com/canonical/lxd-private/pull/87 | patch |
| https://github.com/canonical/lxd-private/pull/105 | patch |
| https://github.com/canonical/lxd-private/pull/104 | patch |
| https://github.com/canonical/lxd-private/pull/103 | patch |
| https://github.com/canonical/lxd-private/pull/84 | patch |
Impacted products
Date Public
2026-09-25 03:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-85526",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T03:55:18.376Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "LXD",
"platforms": [
"Linux"
],
"product": "LXD",
"repo": "https://github.com/canonical/lxd",
"vendor": "Canonical",
"versions": [
{
"lessThan": "4.0.14",
"status": "affected",
"version": "4.0.0",
"versionType": "semver"
},
{
"lessThan": "5.0.10",
"status": "affected",
"version": "5.0.0",
"versionType": "semver"
},
{
"lessThan": "5.21.8",
"status": "affected",
"version": "5.21.0",
"versionType": "semver"
},
{
"lessThan": "6.10",
"status": "affected",
"version": "6.0",
"versionType": "semver"
}
]
}
],
"datePublic": "2026-09-25T03:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvolumes[].path entry in backup/optimized_header.yaml during a btrfs optimized backup import."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Path Traversal"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.9,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T13:21:40.621Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"vendor-advisory",
"issue-tracking"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-h85r-gjgx-g2rv"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd-private/pull/87"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd-private/pull/105"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd-private/pull/104"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd-private/pull/103"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd-private/pull/84"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8, 6.10 or later."
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-85526",
"datePublished": "2026-09-28T13:21:40.621Z",
"dateReserved": "2026-09-04T08:34:29.842Z",
"dateUpdated": "2026-09-29T03:55:18.376Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-86335 (GCVE-0-2026-86335)
Vulnerability from cvelistv5 – Published: 2026-09-28 13:21 – Updated: 2026-09-28 16:32
VLAI
EPSS
VEX
Title
LXD Cross-Project Private Image Theft via Unsanitized GetImageFromAnyProject Local Reuse
Summary
Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance import requests.
Severity
6.3 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-28 13:49 UTC
CWE
- CWE-862 - Missing Authorization
Assigner
References
5 references
| URL | Tags |
|---|---|
| https://github.com/canonical/lxd/security/advisor… | vendor-advisoryissue-tracking |
| https://github.com/canonical/lxd/pull/19003 | patch |
| https://github.com/canonical/lxd/pull/19002 | patch |
| https://github.com/canonical/lxd/pull/19001 | patch |
| https://github.com/canonical/lxd/pull/18987 | patch |
Impacted products
Date Public
2026-09-25 03:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-86335",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T13:49:04.323716Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T16:32:28.655Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "LXD",
"product": "LXD",
"repo": "https://github.com/canonical/lxd",
"vendor": "Canonical",
"versions": [
{
"lessThan": "5.21.8",
"status": "affected",
"version": "5.21.0",
"versionType": "semver"
},
{
"lessThan": "6.10",
"status": "affected",
"version": "6.0",
"versionType": "semver"
},
{
"lessThan": "5.0.10",
"status": "affected",
"version": "4.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Yuliang Xiao"
}
],
"datePublic": "2026-09-25T03:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Missing Authorization in imageDownload in Canonical LXD before 5.0.10,\u00a05.21.8, and 6.10\u00a0on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance import requests."
}
],
"impacts": [
{
"capecId": "CAPEC-122",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-122 Privilege Abuse"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862 Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T13:21:29.891Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"vendor-advisory",
"issue-tracking"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-j7p3-5g2v-69j8"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd/pull/19003"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd/pull/19002"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd/pull/19001"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd/pull/18987"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to LXD versions 5.0.10, 5.21.8, 6.10 or later."
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "LXD Cross-Project Private Image Theft via Unsanitized GetImageFromAnyProject Local Reuse"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-86335",
"datePublished": "2026-09-28T13:21:29.891Z",
"dateReserved": "2026-09-07T08:01:22.942Z",
"dateUpdated": "2026-09-28T16:32:28.655Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-86334 (GCVE-0-2026-86334)
Vulnerability from cvelistv5 – Published: 2026-09-28 13:21 – Updated: 2026-09-28 17:56
VLAI
EPSS
VEX
Title
CLI Path Traversal via Content-Disposition in LXD Image Export/Copy
Summary
Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite arbitrary local files and execute code on the client system via a crafted Content-Disposition header filename parameter during unified image export or copy operations into a local directory target.
Severity
4.2 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-28 17:55 UTC
CWE
- CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://github.com/canonical/lxd/security/advisor… | vendor-advisoryissue-tracking |
| https://github.com/canonical/lxd/pull/18977 | patch |
| https://github.com/canonical/lxd/pull/18976 | patch |
| https://github.com/canonical/lxd/pull/18974 | patch |
| https://github.com/canonical/lxd/pull/18975 | patch |
| https://github.com/canonical/lxd/pull/18940 | patch |
Impacted products
Date Public
2026-09-25 03:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-86334",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T17:55:41.286474Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T17:56:11.126Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-g4cm-f533-78hq"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "LXD",
"platforms": [
"Linux"
],
"product": "LXD",
"repo": "https://github.com/canonical/lxd",
"vendor": "Canonical",
"versions": [
{
"lessThan": "4.0.14",
"status": "affected",
"version": "4.0.2",
"versionType": "semver"
},
{
"lessThan": "5.0.10",
"status": "affected",
"version": "5.0.0",
"versionType": "semver"
},
{
"lessThan": "5.21.8",
"status": "affected",
"version": "5.21.0",
"versionType": "semver"
},
{
"lessThan": "6.10",
"status": "affected",
"version": "6.0",
"versionType": "semver"
}
]
}
],
"datePublic": "2026-09-25T03:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite arbitrary local files and execute code on the client system via a crafted Content-Disposition header filename parameter during unified image export or copy operations into a local directory target."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Path Traversal"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 4.2,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T13:21:15.612Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"vendor-advisory",
"issue-tracking"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-g4cm-f533-78hq"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd/pull/18977"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd/pull/18976"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd/pull/18974"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd/pull/18975"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/lxd/pull/18940"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8, 6.10 or later."
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "CLI Path Traversal via Content-Disposition in LXD Image Export/Copy"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-86334",
"datePublished": "2026-09-28T13:21:15.612Z",
"dateReserved": "2026-09-07T08:01:22.941Z",
"dateUpdated": "2026-09-28T17:56:11.126Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-66897 (GCVE-0-2026-66897)
Vulnerability from cvelistv5 – Published: 2026-08-24 09:08 – Updated: 2026-08-25 03:55
VLAI
EPSS
VEX
Title
Instance template path traversal allows arbitrary host file write as root
Summary
A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in metadata.yaml, LXD validates the path against a confined os.Root directory handle but subsequently opens and creates the file using os.Create with an unconfined string path. This discrepancy between path resolution checks and file creation allows an attacker to escape directory confinement, overwrite root-owned host files, and achieve host root code execution.
Severity
9.9 (Critical)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-24 00:00 UTC
CWE
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://github.com/canonical/lxd/security/advisor… | vdb-entryvendor-advisory |
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-66897",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-24T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T03:55:49.930Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "LXD",
"platforms": [
"Linux"
],
"product": "LXD",
"repo": "https://github.com/canonical/lxd",
"vendor": "Canonical",
"versions": [
{
"lessThan": "4.0.13",
"status": "affected",
"version": "4.0.0",
"versionType": "semver"
},
{
"lessThan": "5.0.9",
"status": "affected",
"version": "5.0.0",
"versionType": "semver"
},
{
"lessThan": "5.21.7",
"status": "affected",
"version": "5.21.0",
"versionType": "semver"
},
{
"lessThan": "6.10",
"status": "affected",
"version": "6.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A path traversal vulnerability in LXD\u0027s instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in metadata.yaml, LXD validates the path against a confined os.Root directory handle but subsequently opens and creates the file using os.Create with an unconfined string path. This discrepancy between path resolution checks and file creation allows an attacker to escape directory confinement, overwrite root-owned host files, and achieve host root code execution."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "Path Traversal"
}
]
},
{
"capecId": "CAPEC-153",
"descriptions": [
{
"lang": "en",
"value": "Input Data Manipulation"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.9,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
},
{
"cweId": "CWE-23",
"description": "CWE-23: Relative Path Traversal",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-24T09:08:04.188Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"vdb-entry",
"vendor-advisory"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-q39m-8fx9-42fv"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to LXD versions 4.0.13, 5.0.9, 5.21.7, 6.10 or later."
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Instance template path traversal allows arbitrary host file write as root"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-66897",
"datePublished": "2026-08-24T09:08:04.188Z",
"dateReserved": "2026-07-28T07:41:26.310Z",
"dateUpdated": "2026-08-25T03:55:49.930Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-77113 (GCVE-0-2026-77113)
Vulnerability from cvelistv5 – Published: 2026-08-20 22:32 – Updated: 2026-08-21 20:08
VLAI
EPSS
VEX
Title
Path Traversal Vulnerability in apport-unpack
Summary
Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in crash report files.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-21 19:50 UTC
CWE
- CWE-23 - Relative path traversal
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://launchpad.net/bugs/2161697 | issue-trackingvendor-advisory |
| https://github.com/canonical/apport/pull/646 | patch |
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-77113",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-21T19:50:19.847915Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-21T20:08:37.866Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "apport-unpack",
"platforms": [
"Linux"
],
"product": "Apport",
"programFiles": [
"problem_report.py"
],
"repo": "https://github.com/canonical/apport",
"vendor": "Canonical",
"versions": [
{
"lessThan": "2.36.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "2.34.2",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "2.28.4",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:canonical:apport:*:*:linux:*:*:*:*:*",
"versionEndExcluding": "2.36.0",
"versionStartIncluding": "0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:canonical:apport:*:*:linux:*:*:*:*:*",
"versionEndExcluding": "2.34.2",
"versionStartIncluding": "0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:canonical:apport:*:*:linux:*:*:*:*:*",
"versionEndExcluding": "2.28.4",
"versionStartIncluding": "0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Sakib Sarkar (0xROI)"
}
],
"descriptions": [
{
"lang": "en",
"value": "Path traversal in apport-unpack in Canonical Apport before\u00a02.36.0,\u00a02.34.2, and\u00a02.28.4\u00a0on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in crash report files."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Path Traversal"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "LOCAL",
"baseScore": 6.7,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "ACTIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-23",
"description": "CWE-23 Relative path traversal",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-20T22:32:51.447Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"issue-tracking",
"vendor-advisory"
],
"url": "https://launchpad.net/bugs/2161697"
},
{
"tags": [
"patch"
],
"url": "https://github.com/canonical/apport/pull/646"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Path Traversal Vulnerability in apport-unpack",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-77113",
"datePublished": "2026-08-20T22:32:51.447Z",
"dateReserved": "2026-08-20T11:53:23.292Z",
"dateUpdated": "2026-08-21T20:08:37.866Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-61898 (GCVE-0-2026-61898)
Vulnerability from cvelistv5 – Published: 2026-08-20 14:32 – Updated: 2026-08-26 19:50
VLAI
EPSS
VEX
Title
accountsservice: shell injection via attacker-controlled ~/.pam_environment in Ubuntu language helper scripts
Summary
The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject a sed 'e' flag and arbitrary shell commands that execute with the privileges of the AccountsService helper process (real UID 0) via the SetLanguage D-Bus method.
Severity
7.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-26 19:43 UTC
CWE
- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://bugs.launchpad.net/ubuntu/+source/account… | issue-tracking |
| https://ubuntu.com/security/CVE-2026-61898 | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Canonical | accountsservice |
Affected:
22.07.5-2ubuntu1 , < 22.07.5-2ubuntu1.6
(dpkg)
Affected: 23.13.9-2ubuntu6 , < 23.13.9-2ubuntu6.1 (dpkg) Affected: 23.13.9-8ubuntu5 , < 23.13.9-8ubuntu5.2 (dpkg) Affected: 23.13.9-8ubuntu6 , < 23.13.9-8ubuntu7 (dpkg) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-61898",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-26T19:43:44.504304Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-26T19:50:34.552Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "accountsservice",
"platforms": [
"Ubuntu 14.04 LTS",
"Ubuntu 16.04 LTS",
"Ubuntu 18.04 LTS",
"Ubuntu 20.04 LTS",
"Ubuntu 22.04 LTS",
"Ubuntu 24.04 LTS",
"Ubuntu 26.04 LTS",
"Ubuntu 26.10"
],
"product": "accountsservice",
"vendor": "Canonical",
"versions": [
{
"lessThan": "22.07.5-2ubuntu1.6",
"status": "affected",
"version": "22.07.5-2ubuntu1",
"versionType": "dpkg"
},
{
"lessThan": "23.13.9-2ubuntu6.1",
"status": "affected",
"version": "23.13.9-2ubuntu6",
"versionType": "dpkg"
},
{
"lessThan": "23.13.9-8ubuntu5.2",
"status": "affected",
"version": "23.13.9-8ubuntu5",
"versionType": "dpkg"
},
{
"lessThan": "23.13.9-8ubuntu7",
"status": "affected",
"version": "23.13.9-8ubuntu6",
"versionType": "dpkg"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Deutsche Telekom Security GmbH Red Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject a sed \u0027e\u0027 flag and arbitrary shell commands that execute with the privileges of the AccountsService helper process (real UID 0) via the SetLanguage D-Bus method."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-20T14:32:59.924Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"name": "Launchpad Bug #2157985",
"tags": [
"issue-tracking"
],
"url": "https://bugs.launchpad.net/ubuntu/+source/accountsservice/+bug/2157985"
},
{
"name": "Ubuntu CVE Tracker",
"tags": [
"vendor-advisory"
],
"url": "https://ubuntu.com/security/CVE-2026-61898"
}
],
"title": "accountsservice: shell injection via attacker-controlled ~/.pam_environment in Ubuntu language helper scripts"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-61898",
"datePublished": "2026-08-20T14:32:59.924Z",
"dateReserved": "2026-07-11T18:43:51.251Z",
"dateUpdated": "2026-08-26T19:50:34.552Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-61897 (GCVE-0-2026-61897)
Vulnerability from cvelistv5 – Published: 2026-08-20 14:32 – Updated: 2026-08-26 19:50
VLAI
EPSS
VEX
Title
accountsservice: incomplete privilege drop when running Ubuntu-specific language helper scripts
Summary
An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to root, enabling local privilege escalation.
Severity
7.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-26 19:43 UTC
CWE
- CWE-273 - Improper Check for Dropped Privileges
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://bugs.launchpad.net/ubuntu/+source/account… | issue-tracking |
| https://ubuntu.com/security/CVE-2026-61897 | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Canonical | accountsservice |
Affected:
22.07.5-2ubuntu1 , < 22.07.5-2ubuntu1.6
(dpkg)
Affected: 23.13.9-2ubuntu6 , < 23.13.9-2ubuntu6.1 (dpkg) Affected: 23.13.9-8ubuntu5 , < 23.13.9-8ubuntu5.2 (dpkg) Affected: 23.13.9-8ubuntu6 , < 23.13.9-8ubuntu7 (dpkg) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-61897",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-26T19:43:37.600246Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-26T19:50:49.398Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "accountsservice",
"platforms": [
"Ubuntu 14.04 LTS",
"Ubuntu 16.04 LTS",
"Ubuntu 18.04 LTS",
"Ubuntu 20.04 LTS",
"Ubuntu 22.04 LTS",
"Ubuntu 24.04 LTS",
"Ubuntu 26.04 LTS",
"Ubuntu 26.10"
],
"product": "accountsservice",
"vendor": "Canonical",
"versions": [
{
"lessThan": "22.07.5-2ubuntu1.6",
"status": "affected",
"version": "22.07.5-2ubuntu1",
"versionType": "dpkg"
},
{
"lessThan": "23.13.9-2ubuntu6.1",
"status": "affected",
"version": "23.13.9-2ubuntu6",
"versionType": "dpkg"
},
{
"lessThan": "23.13.9-8ubuntu5.2",
"status": "affected",
"version": "23.13.9-8ubuntu5",
"versionType": "dpkg"
},
{
"lessThan": "23.13.9-8ubuntu7",
"status": "affected",
"version": "23.13.9-8ubuntu6",
"versionType": "dpkg"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Deutsche Telekom Security GmbH Red Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to root, enabling local privilege escalation."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-273",
"description": "CWE-273: Improper Check for Dropped Privileges",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-20T14:32:53.827Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"name": "Launchpad Bug #2157985",
"tags": [
"issue-tracking"
],
"url": "https://bugs.launchpad.net/ubuntu/+source/accountsservice/+bug/2157985"
},
{
"name": "Ubuntu CVE Tracker",
"tags": [
"vendor-advisory"
],
"url": "https://ubuntu.com/security/CVE-2026-61897"
}
],
"title": "accountsservice: incomplete privilege drop when running Ubuntu-specific language helper scripts"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-61897",
"datePublished": "2026-08-20T14:32:53.827Z",
"dateReserved": "2026-07-11T18:43:51.251Z",
"dateUpdated": "2026-08-26T19:50:49.398Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}