Link following in LXD - CVE-2026-87798

 

Link following in LXD - CVE-2026-87798

Published: September 25, 2026


Vulnerability identifier: #VU152250
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-87798
CWE-ID: CWE-59
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to write attacker-controlled files to arbitrary paths on the machine running the CLI with the operator's privileges.

The vulnerability exists due to improper handling of inconsistent directory entries in sftpRecursivePullFile when recursively pulling files from a compromised virtual machine. A remote user can return the same entry name with inconsistent file types to write through a previously created symbolic link to arbitrary paths.

User interaction is required because an operator must run a recursive file pull from the compromised virtual machine. Containers are not affected.


Affected software

LXD

How to mitigate CVE-2026-87798

Install security update from vendor's website.

LXD - addressed in versions 4.0.14, 5.0.10, 5.21.8

External References

Related Security Bulletins