PT-2026-99894 · Canonical · Lxd

·

CVE-2026-87798

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v3.1

5.8

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Canonical LXD versions 4.0.2 through 4.0.13 Canonical LXD versions 5.0.0 through 5.0.9 Canonical LXD versions 5.1.0 through 5.21.7 Canonical LXD versions 6.0.0 through 6.9
Description Improper link resolution in the recursive file pull feature of the CLI client allows an attacker with root access inside a virtual machine to write controlled files or directory trees to arbitrary paths on the client host using the operator's privileges. This is achieved by employing a modified lxd-agent that provides inconsistent SFTP directory listings and Lstat results.
Recommendations Update to version 4.0.14 Update to version 5.0.10 Update to version 5.21.8 Update to a version later than 6.9

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-87798
GHSA-MR8V-HX34-HFVF

Affected Products

Lxd