LXD 4.0.2-6.10 Path Traversal via CLI Image Export/Copy (CVE-2026-86334)
CVE-2026-86334 Published on September 28, 2026
CLI Path Traversal via Content-Disposition in LXD Image Export/Copy
Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite arbitrary local files and execute code on the client system via a crafted Content-Disposition header filename parameter during unified image export or copy operations into a local directory target.
Vulnerability Analysis
CVE-2026-86334 is exploitable with network access, requires user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, with no impact on integrity and availability.
Weakness Type
What is a Directory traversal Vulnerability?
The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVE-2026-86334 has been classified to as a Directory traversal vulnerability or weakness.
Products Associated with CVE-2026-86334
Want to know whenever a new CVE is published for Canonical Lxd? stack.watch will email you.
Affected Versions
Canonical LXD:- Version 4.0.2 and below 4.0.14 is affected.
- Version 5.0.0 and below 5.0.10 is affected.
- Version 5.21.0 and below 5.21.8 is affected.
- Version 6.0 and below 6.10 is affected.