CVE-2026-86335
6.3
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Summary
Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance import requests.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Canonical | LXD | 5.21.0 < 5.21.8 | affected |
| Canonical | LXD | 6.0 < 6.10 | affected |
| Canonical | LXD | 4.0 < 5.0.10 | affected |
Weaknesses
- CWE-862: CWE-862 Missing Authorization
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://github.com/canonical/lxd/security/advisories/GHSA-j7p3-5g2v-69j8
- https://github.com/canonical/lxd/pull/19003
- https://github.com/canonical/lxd/pull/19002
- https://github.com/canonical/lxd/pull/19001
- https://github.com/canonical/lxd/pull/18987
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.