Canonical LXD CLI Improper Link Resolution in 4.0.2-6.9
CVE-2026-87798 Published on September 28, 2026

LXD client recursive file pull allows directory escape via malicious VM agent
Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine to write attacker-controlled files or directory trees to arbitrary paths on the client host, with the operator's privileges. The attacker does this by using a modified lxd-agent that returns inconsistent SFTP directory listings and Lstat results.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-87798 is exploitable with network access, requires user interaction and a small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
LOW
User Interaction:
REQUIRED
Scope:
CHANGED
Confidentiality Impact:
NONE
Integrity Impact:
HIGH
Availability Impact:
NONE

Weakness Type

What is an insecure temporary file Vulnerability?

The software attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

CVE-2026-87798 has been classified to as an insecure temporary file vulnerability or weakness.


Products Associated with CVE-2026-87798

Want to know whenever a new CVE is published for Canonical Lxd? stack.watch will email you.

 

Affected Versions

Canonical LXD: