CVE-2026-3351: Canonical Lxd

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, restricted user to enumerate all certificate fingerprints trusted by the lxd server.

Affected products

Published 2026-03-03. Last modified 2026-06-17.