PT-2026-52844 · Canonical · Lxd

·

CVE-2026-9640

·

Published

2026-06-26

·

Updated

2026-07-02

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LXD versions 6.0 through 6.8 LXD versions 5.21.0 through 5.21.4 LXD versions 5.0.0 through 5.0.6
Description An issue exists in the handling of project-restriction policies during snapshot restoration. An authenticated project operator in a restricted multi-tenant environment can bypass policy restrictions by importing a maliciously crafted instance backup that contains restricted configuration keys within a snapshot. These keys are applied to the live instance without policy validation upon restoration. Starting the modified instance allows the operator to obtain unauthorized host root access.
Recommendations Update LXD to version 6.9 or later. Update LXD to version 5.21.5 or later. Update LXD to version 5.0.7 or later.

Exploit

Fix

LPE

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9640
GHSA-PPQ7-4492-5552

Affected Products

Lxd