Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-66898: LXD Backup Data Tampering Enables Root File Access

CVE-2026-66898 · published 22 days ago
Summary

An attacker can manipulate file paths and overwrite files on the system by creating a malicious backup archive for LXD. This could lead to unauthorized access or data loss. Update LXD to the latest version to address this vulnerability.

What to do
  • Update canonical lxd to version 4.0.12 or later.
Affected software
Ecosystem VendorProductAffected versions
– canonical lxd < 4.0.12
Debian:12 debian lxd All versions
Debian:13 debian lxd All versions
Original advisory text
A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to vali...
A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside the designated restore directory.
Severity
9.9 Critical
CVSS 3.1: 9.9 (MITRE)
CVSS 3.1: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-22Path Traversal
Timeline
Published12 Aug 2026
Updated30 Aug 2026
First seen12 Aug 2026
Sources
CVE-2026-66898 · MITRE
Monitor software like this
Free during beta