Canonical · Lxd · CVE-2026-12411
**Name of the Vulnerable Software and Affected Versions**
Canonical LXD (affected versions not specified)
**Description**
Broken Access Control in the `devLXDInstancePatchHandler` component allows an untrusted guest to mount, read, and overwrite the custom storage volume of another guest. This is achieved by sending a crafted device PATCH request over the `/dev/lxd` endpoint when the `security.devlxd.management.volumes` setting is enabled.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Disable the `security.devlxd.management.volumes` setting to prevent the exploitation of this issue.