Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4344 articles · 196410 vulns · 36/41 feeds (7d)
← Back to list
9.9
CVE-2026-66897PATCHED
canonical · lxd

Instance template path traversal allows arbitrary host file write as root

Description

A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in metadata.yaml, LXD validates the path against a confined os.Root directory handle but subsequently opens and creates the file using os.Create with an unconfined string path. This discrepancy between path resolution checks and file creation allows an attacker to escape directory confinement, overwrite root-owned host files, and achieve host root code execution.

Affected Products

VendorProductVersions
canonicallxd4.0.0, 5.0.0, 5.21.0, 6.0

References

  • https://github.com/canonical/lxd/security/advisories/GHSA-q39m-8fx9-42fv(vdb-entry, vendor-advisory)

Related News (1 articles)

Tier C
VulDB1h ago
CVE-2026-66897 | Canonical LXD up to 4.0.12/5.0.8/5.21.6/6.9 Instance Template Processing metadata.yaml os.Create path traversal
→ No new info (linked only)
CVSS 3.19.9 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
4.0.135.0.95.21.76.10
CWECWE-22, CWE-23
PublishedAug 24, 2026
Trending Score30
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-62941
Incus: Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge
Trending: 30
CRITICALCVE-2026-63125
Incus vulnerable to root RCE via image backup.yaml symlink
Trending: 30
HIGHCVE-2026-55622
Incus has a project restriction bypass in instance copy across projects
Trending: 24
CRITICALCVE-2026-62867
Incus has an argument injection in storage volume block.create_options that leads to arbitrary command execution
Trending: 24
CRITICALCVE-2026-62940
Incus has a project restriction bypass via instance migration config override
Trending: 24

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 24, 2026
Patch Available
Aug 24, 2026
Discovered by ZDM
Aug 24, 2026