CVE-2026-66898: Canonical Lxd

Critical severity, CVSS 9.9. EPSS: 0.6% chance of exploitation in the next 30 days.

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside the designated restore directory.

Affected products

  • Canonical Lxd: from 4.0.0, before 4.0.12 (fixed in 4.0.12); from 5.0.0, before 5.0.4 (fixed in 5.0.4); from 5.1, before 5.21.2 (fixed in 5.21.2); version 6.0 only

Published 2026-08-12. Last modified 2026-09-11.