Path traversal in LXD - CVE-2026-86334

 

Path traversal in LXD - CVE-2026-86334

Published: September 25, 2026


Vulnerability identifier: #VU152256
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-86334
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to overwrite arbitrary files on the client.

The vulnerability exists due to path traversal in the unified image export and copy handling of the CLI when processing a server-controlled Content-Disposition filename for an image exported to a directory target. A remote attacker can provide a crafted filename containing path traversal sequences to overwrite files outside the export directory.

User interaction is required because the victim must export or copy an image from the malicious server to a directory target.


Affected software

LXD

How to mitigate CVE-2026-86334

Install security update from vendor's website.

LXD - addressed in versions 4.0.14, 5.0.10, 5.21.8, 6.10

External References

Related Security Bulletins