Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-87799: LXD can let an attacker write any file as root
CVE-2026-87799 · published 4 days ago
Summary
Versions of Canonical LXD for Linux can be tricked into placing a symbolic link during a migration, letting an authorized user or a malicious source server write files anywhere on the host. Because the files are created with root privileges, this can give the attacker full control of the server. Upgrade LXD to the latest patched releases or apply the vendor’s recommended update to close the risk.
What to do
- Update canonical lxd to version 4.0.14 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | canonical | lxd | < 4.0.14 |
| Debian:12 | debian | lxd | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | lxd | All versions |
Original advisory text
Arbitrary file write on LXD host via symlink in migration stream
Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a project, or a malicious migration source server, to write attacker-controlled files to arbitrary paths on the target host as root, leading to full host compromise. The attacker does this with a crafted rsync or btrfs send stream that plants a symlink in the transferred volume, such as rootfs or root.img, and then writes through it.
References
- https://github.com/canonical/lxd/security/advisories/GHSA-fmc3-3cpq-6whr Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-87799 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87799... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-87799 Vendor Advisory
- https://github.com/canonical/lxd Product
- https://ubuntu.com/security/CVE-2026-87799 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-87799 Third Party Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-59Link Following
Timeline
Published28 Sep 2026
Updated1 Oct 2026
First seen28 Sep 2026
Sources
CVE-2026-87799 · NVD
CVE-2026-87799 · MITRE
DEBIAN-CVE-2026-87799 · OSV
UBUNTU-CVE-2026-87799 · OSV
CVE-2026-87799 · OSV
GHSA-fmc3-3cpq-6whr · GHSA
Track software like this
Free during beta