Improper Link Resolution in Canonical LXD CLI Client
CVE-2026-87798

5.8MEDIUM

Key Information:

Vendor

Canonical

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-87798?

The LXD CLI client in Canonical LXD versions prior to 4.0.14, 5.0.10, and 5.21.8 is affected by a vulnerability due to improper link resolution within its recursive file pull feature. This flaw allows an attacker who has root access to a virtual machine to manipulate file structures leading to unauthorized file writes on the client host, utilizing altered SFTP directory listings. An attacker can exploit this vulnerability and gain further access based on the privileges granted to the operator.

Affected Version(s)

LXD Linux 4.0.2 < 4.0.14

LXD Linux 5.0.0 < 5.0.10

LXD Linux 5.21.0 < 5.21.8

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.