Path Traversal Vulnerability in Canonical LXD CLI Client
CVE-2026-86334

4.2MEDIUM

Key Information:

Vendor

Canonical

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-86334?

A path traversal vulnerability exists in the CLI client of Canonical LXD that can be exploited during image export and copy operations. This flaw allows a remote attacker or a machine-in-the-middle image server to manipulate the Content-Disposition header, potentially overwriting arbitrary local files and executing arbitrary code on the client system. Affected versions include Canonical LXD from 4.0.2 prior to 4.0.14, 5.0.10, 5.21.8, and 6.10 across all platforms. Users should apply the necessary patches to mitigate this issue.

Affected Version(s)

LXD Linux 4.0.2 < 4.0.14

LXD Linux 5.0.0 < 5.0.10

LXD Linux 5.21.0 < 5.21.8

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.