PT-2026-99892 · Canonical · Lxd

·

CVE-2026-86335

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v3.1

6.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Canonical LXD versions prior to 5.0.10 Canonical LXD versions prior to 5.21.8 Canonical LXD versions prior to 6.10
Description An authorization flaw exists in the imageDownload() function on Linux. This issue allows a client restricted to a specific project to access private images belonging to other projects by reusing local fingerprints during requests to import images or instances.
Recommendations Update to version 5.0.10 or later. Update to version 5.21.8 or later. Update to version 6.10 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86335
GHSA-J7P3-5G2V-69J8

Affected Products

Lxd