Improper Link Resolution in Canonical LXD CLI Client
CVE-2026-87798
5.8MEDIUM
What is CVE-2026-87798?
The LXD CLI client in Canonical LXD versions prior to 4.0.14, 5.0.10, and 5.21.8 is affected by a vulnerability due to improper link resolution within its recursive file pull feature. This flaw allows an attacker who has root access to a virtual machine to manipulate file structures leading to unauthorized file writes on the client host, utilizing altered SFTP directory listings. An attacker can exploit this vulnerability and gain further access based on the privileges granted to the operator.
Affected Version(s)
LXD Linux 4.0.2 < 4.0.14
LXD Linux 5.0.0 < 5.0.10
LXD Linux 5.21.0 < 5.21.8
