Link following in LXD - CVE-2026-87799

 

Link following in LXD - CVE-2026-87799

Published: September 25, 2026


Vulnerability identifier: #VU152251
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-87799
CWE-ID: CWE-59
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to write attacker-controlled files to arbitrary paths on the target host.

The vulnerability exists due to improper handling of symbolic links in the migration stream receiver when receiving an instance or custom storage volume through migration. A remote user can supply a crafted migration stream containing a symbolic link that causes later entries to be written through it to write attacker-controlled files to arbitrary paths on the target host.

For virtual machines, a crafted stream can replace the root.img block file with a symbolic link before the block stream is written through it.


Affected software

LXD

How to mitigate CVE-2026-87799

Install security update from vendor's website.

LXD - addressed in versions 4.0.14, 5.0.10, 5.21.8, 6.10

External References

Related Security Bulletins