Path Traversal Vulnerability in LXD by Canonical
CVE-2026-16033

8.5HIGH

Key Information:

Vendor

Canonical

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-16033?

A path traversal vulnerability exists in LXD, enabling attackers to read arbitrary host files or create files without restrictions. This issue arises when LXD processes image metadata templates without properly sanitizing or restricting paths, allowing crafted image archives with malicious directives to escape the instance templates directory. As a result, it can inadvertently expose files on the host system, potentially compromising sensitive data.

Affected Version(s)

LXD Linux 4.0.0 < 4.0.12

LXD Linux 5.0.0 < 5.0.8

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.