Privilege Escalation Vulnerability in LXD by Canonical
CVE-2026-9640
7.2HIGH
What is CVE-2026-9640?
A vulnerability exists in LXD versions prior to 6.9, 5.21.5, and 5.0.7, where an authenticated project operator in a restricted multi-tenant environment can exploit project-restriction policies. By using a maliciously crafted instance backup during snapshot restoration, the operator can bypass policy restrictions. This allows unauthorized application of restricted configuration keys to a live instance, ultimately granting the operator host root access.
Affected Version(s)
LXD Linux 5.21.0 < 5.21.5
LXD Linux 5.0.0 < 5.0.7
LXD Linux 6.0 < 6.9
