PT-2026-99891 · Canonical · Lxd

·

CVE-2026-86334

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Canonical LXD versions 4.0.2 through 4.0.13 Canonical LXD version 5.0.10 Canonical LXD version 5.21.8 Canonical LXD version 6.10
Description A path traversal issue exists in the CLI client image export and copy functionality. A remote malicious or machine-in-the-middle image server can overwrite arbitrary local files and execute code on the client system. This is achieved by using a crafted filename parameter within the Content-Disposition header during unified image export or copy operations targeting a local directory.
Recommendations Update Canonical LXD version 4.0.2 through 4.0.13 to version 4.0.14. Update Canonical LXD version 5.0.10 to a newer version. Update Canonical LXD version 5.21.8 to a newer version. Update Canonical LXD version 6.10 to a newer version.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86334
GHSA-G4CM-F533-78HQ

Affected Products

Lxd