Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-87799: LXD can let an attacker write any file as root

CVE-2026-87799 · published 4 days ago
Summary

Versions of Canonical LXD for Linux can be tricked into placing a symbolic link during a migration, letting an authorized user or a malicious source server write files anywhere on the host. Because the files are created with root privileges, this can give the attacker full control of the server. Upgrade LXD to the latest patched releases or apply the vendor’s recommended update to close the risk.

What to do
  • Update canonical lxd to version 4.0.14 or later.
Affected software
Ecosystem VendorProductAffected versions
– canonical lxd < 4.0.14
Debian:12 debian lxd All versions
Ubuntu:Pro:16.04:LTS canonical lxd All versions
Original advisory text
Arbitrary file write on LXD host via symlink in migration stream
Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a project, or a malicious migration source server, to write attacker-controlled files to arbitrary paths on the target host as root, leading to full host compromise. The attacker does this with a crafted rsync or btrfs send stream that plants a symlink in the transferred volume, such as rootfs or root.img, and then writes through it.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.9 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-59Link Following
Timeline
Published28 Sep 2026
Updated1 Oct 2026
First seen28 Sep 2026
Track software like this
Free during beta