Missing Authorization in LXD - CVE-2026-86335
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose private image properties and files from another project.
The vulnerability exists due to missing authorization in the imageDownload image reuse logic when processing image import requests that reference a private image fingerprint. A remote user can submit an image import request referencing a known private image fingerprint to disclose private image properties and files from another project.
Exploitation requires image creation permissions in the requesting project.