Missing Authorization in LXD - CVE-2026-86335

 

Missing Authorization in LXD - CVE-2026-86335

Published: September 25, 2026


Vulnerability identifier: #VU152255
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-86335
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose private image properties and files from another project.

The vulnerability exists due to missing authorization in the imageDownload image reuse logic when processing image import requests that reference a private image fingerprint. A remote user can submit an image import request referencing a known private image fingerprint to disclose private image properties and files from another project.

Exploitation requires image creation permissions in the requesting project.


Affected software

LXD

How to mitigate CVE-2026-86335

Install security update from vendor's website.

LXD - addressed in versions 5.0.10, 5.21.8, 6.10

External References

Related Security Bulletins