Btrfs Storage Driver Path Traversal in Canonical LXD
CVE-2026-85526 Published on September 28, 2026
Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD
Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvolumes[].path entry in backup/optimized_header.yaml during a btrfs optimized backup import.
Vulnerability Analysis
CVE-2026-85526 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. Public availability of a proof of concept (POC) exploit exists for CVE-2026-85526. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Weakness Type
What is a Directory traversal Vulnerability?
The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVE-2026-85526 has been classified to as a Directory traversal vulnerability or weakness.
Products Associated with CVE-2026-85526
Want to know whenever a new CVE is published for Canonical Lxd? stack.watch will email you.
Affected Versions
Canonical LXD:- Version 4.0.0 and below 4.0.14 is affected.
- Version 5.0.0 and below 5.0.10 is affected.
- Version 5.21.0 and below 5.21.8 is affected.
- Version 6.0 and below 6.10 is affected.