Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-66898: LXD Backup Data Tampering Enables Root File Access
CVE-2026-66898 · published 22 days ago
Summary
An attacker can manipulate file paths and overwrite files on the system by creating a malicious backup archive for LXD. This could lead to unauthorized access or data loss. Update LXD to the latest version to address this vulnerability.
What to do
- Update canonical lxd to version 4.0.12 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | canonical | lxd | < 4.0.12 |
| Debian:12 | debian | lxd | All versions |
| Debian:13 | debian | lxd | All versions |
Original advisory text
A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to vali...
A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside the designated restore directory.
References
- https://github.com/canonical/lxd/security/advisories/GHSA-m857-c7gc-c984 vdb-entry vendor-advisory
- https://security-tracker.debian.org/tracker/CVE-2026-66898 Vendor Advisory
Severity
9.9
Critical
CVSS 3.1: 9.9 (MITRE)
CVSS 3.1: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-22Path Traversal
Timeline
Published12 Aug 2026
Updated30 Aug 2026
First seen12 Aug 2026
Monitor software like this
Free during beta