Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5071 articles · 189145 vulns · 37/41 feeds (7d)
← Back to list
9.9
CVE-2026-66898PATCHED
canonical · lxd

Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE

Description

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside the designated restore directory.

Affected Products

VendorProductVersions
canonicallxd4.0.0, 5.0.0, 5.21.0, 6.0

References

  • https://github.com/canonical/lxd/security/advisories/GHSA-m857-c7gc-c984(vdb-entry, vendor-advisory)

Related News (1 articles)

Tier C
VulDB2h ago
CVE-2026-66898 | Canonical LXD up to 4.0.11/5.0.3/5.21.1/6.0 Backup Import path traversal
→ No new info (linked only)
CVSS 3.19.9 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
4.0.125.0.45.21.26.1
CWECWE-22
PublishedAug 12, 2026
Trending Score30
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-62420
Cross-project cluster migration bypasses project restrictions via cluster notification flag
Trending: 35
HIGHCVE-2026-63299
Storage volume cross-project move and snapshot restore bypass project disk limits
Trending: 32
CRITICALCVE-2026-63293
Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root
Trending: 30
CRITICALCVE-2026-63294
Root RCE via image backup.yaml symlink
Trending: 30
CRITICALCVE-2026-63297
Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge
Trending: 30

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 12, 2026
Discovered by ZDM
Aug 12, 2026
Patch Available
Aug 12, 2026