Canonical LXD CLI Improper Link Resolution in 4.0.2-6.9
CVE-2026-87798 Published on September 28, 2026
LXD client recursive file pull allows directory escape via malicious VM agent
Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine to write attacker-controlled files or directory trees to arbitrary paths on the client host, with the operator's privileges. The attacker does this by using a modified lxd-agent that returns inconsistent SFTP directory listings and Lstat results.
Vulnerability Analysis
CVE-2026-87798 is exploitable with network access, requires user interaction and a small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.
Weakness Type
What is an insecure temporary file Vulnerability?
The software attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CVE-2026-87798 has been classified to as an insecure temporary file vulnerability or weakness.
Products Associated with CVE-2026-87798
Want to know whenever a new CVE is published for Canonical Lxd? stack.watch will email you.
Affected Versions
Canonical LXD:- Version 4.0.2 and below 4.0.14 is affected.
- Version 5.0.0 and below 5.0.10 is affected.
- Version 5.21.0 and below 5.21.8 is affected.
- Version 6.0 and below 6.9 is affected.