CVE-2026-3351: Canonical Lxd
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, restricted user to enumerate all certificate fingerprints trusted by the lxd server.
Affected products
- Canonical Lxd: version 6.6 only
Published 2026-03-03. Last modified 2026-06-17.