CVE-2026-86334
Publication date 29 September 2026
Last updated 30 September 2026
Ubuntu priority
Cvss 3 Severity Score
Description
Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite arbitrary local files and execute code on the client system via a crafted Content-Disposition header filename parameter during unified image export or copy operations into a local directory target.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| lxd | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
Severity score breakdown
CVSS version: CVSS v3.0
Base score
4.2 · Medium
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2026-86334
- https://github.com/canonical/lxd/security/advisories/GHSA-g4cm-f533-78hq
- https://github.com/canonical/lxd/pull/18940
- https://github.com/canonical/lxd/pull/18974
- https://github.com/canonical/lxd/pull/18975
- https://github.com/canonical/lxd/pull/18976
- https://github.com/canonical/lxd/pull/18977