CVE-2026-66898: Canonical Lxd
Critical severity, CVSS 9.9. EPSS: 0.6% chance of exploitation in the next 30 days.
A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside the designated restore directory.
Affected products
- Canonical Lxd: from 4.0.0, before 4.0.12 (fixed in 4.0.12); from 5.0.0, before 5.0.4 (fixed in 5.0.4); from 5.1, before 5.21.2 (fixed in 5.21.2); version 6.0 only
Published 2026-08-12. Last modified 2026-09-11.