← Back to CVE List
CVE-2026-66898NVD
Vulnerability Summary
A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside the designated restore directory.
CVSS v3.1 Base Metrics — Score 9.9 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Canonical Lxd >= 4.0.0 and < 4.0.12
- Canonical Lxd >= 5.0.0 and < 5.0.4
- Canonical Lxd >= 5.1 and < 5.21.2
- Canonical Lxd
- Canonical Lxd 4.0.12
- Canonical Lxd 5.0.4
- Canonical Lxd 5.21.2