CVE-2026-86335: Canonical Lxd

Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance import requests.

Affected products

  • Canonical Lxd: from 5.21.0, before 5.21.8 (fixed in 5.21.8); from 6.0, before 6.10 (fixed in 6.10); from 4.0, before 5.0.10 (fixed in 5.0.10)

Published 2026-09-28. Last modified 2026-09-28.