Missing Authorization in LXD - CVE-2026-97335
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in the custom storage volume copy handling of the POST /1.0/storage-pools/{pool}/volumes/custom endpoint when processing a crafted request that omits source.type. A remote user can submit a request with a caller-controlled source project to disclose sensitive information.
Exploitation requires permission to create custom storage volumes in a project.