Root cmd exec via symlinked backup.yaml in LXD
CVE-2026-63294 Published on August 12, 2026
Root RCE via image backup.yaml symlink
A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml file when it exists as a symbolic link. An attacker can exploit this flaw by providing a malicious archive with a symlinked backup.yaml file, causing LXD to process unconfined configuration metadata and execute arbitrary commands with root privileges.
Vulnerability Analysis
CVE-2026-63294 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. Public availability of a proof of concept (POC) exploit exists for CVE-2026-63294. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Weakness Type
What is an insecure temporary file Vulnerability?
The software attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CVE-2026-63294 has been classified to as an insecure temporary file vulnerability or weakness.
Products Associated with CVE-2026-63294
Want to know whenever a new CVE is published for Canonical Lxd? stack.watch will email you.
Affected Versions
Canonical LXD:- Version 4.0.0 and below 4.0.12 is affected.
- Version 5.0.0 and below 5.0.8 is affected.
- Version 5.21.0 and below 5.21.6 is affected.
- Version 6.0 and below 6.10 is affected.