Improper access control in LXD - CVE-2026-55621
Published: June 29, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the custom volume copy path when handling storage volume copy requests across projects. A remote user can send a specially crafted request with an attacker-controlled source project to disclose sensitive information.
Exploitation requires knowledge of the source project name and the custom volume name, and the copy must occur on the same server.
Affected software
Debian Linux
lxd (Debian package)
How to mitigate CVE-2026-55621
lxd (Debian package) - update to 5.0.2+git20231211.1364ae4-9+deb13u7