Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5065 articles · 189145 vulns · 37/41 feeds (7d)
← Back to list
9.9
CVE-2026-63294PATCHED
canonical · lxd

Root RCE via image backup.yaml symlink

Description

A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml file when it exists as a symbolic link. An attacker can exploit this flaw by providing a malicious archive with a symlinked backup.yaml file, causing LXD to process unconfined configuration metadata and execute arbitrary commands with root privileges.

Affected Products

VendorProductVersions
canonicallxd4.0.0, 5.0.0, 5.21.0, 6.0

References

  • https://github.com/canonical/lxd/security/advisories/GHSA-fv82-v4fj-mm4m(vdb-entry, vendor-advisory)

Related News (1 articles)

Tier C
VulDB3h ago
CVE-2026-63294 | Canonical LXD up to 4.0.11/5.0.7/5.21.5/6.9 Symlink backup.yaml symlink
→ No new info (linked only)
CVSS 3.19.9 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
4.0.125.0.85.21.66.10
CWECWE-59
PublishedAug 12, 2026
Trending Score30
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-62420
Cross-project cluster migration bypasses project restrictions via cluster notification flag
Trending: 35
HIGHCVE-2026-63299
Storage volume cross-project move and snapshot restore bypass project disk limits
Trending: 32
CRITICALCVE-2026-63293
Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root
Trending: 30
CRITICALCVE-2026-66898
Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE
Trending: 30
CRITICALCVE-2026-63297
Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge
Trending: 30

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 12, 2026
Patch Available
Aug 12, 2026
Discovered by ZDM
Aug 12, 2026