Path Traversal Vulnerability in Canonical LXD CLI Client
CVE-2026-86334
4.2MEDIUM
What is CVE-2026-86334?
A path traversal vulnerability exists in the CLI client of Canonical LXD that can be exploited during image export and copy operations. This flaw allows a remote attacker or a machine-in-the-middle image server to manipulate the Content-Disposition header, potentially overwriting arbitrary local files and executing arbitrary code on the client system. Affected versions include Canonical LXD from 4.0.2 prior to 4.0.14, 5.0.10, 5.21.8, and 6.10 across all platforms. Users should apply the necessary patches to mitigate this issue.
Affected Version(s)
LXD Linux 4.0.2 < 4.0.14
LXD Linux 5.0.0 < 5.0.10
LXD Linux 5.21.0 < 5.21.8
