CVE-2026-34179
Received
Received - Intake
Privilege Escalation in Canonical LXD TLS Certificate Handling
Publication date: 2026-04-09
Last updated on: 2026-04-22
Assigner: Canonical Ltd.
Description
Description
In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests to /1.0/certificates/{fingerprint} for restricted TLS certificate users, allowing a remote authenticated attacker to escalate privileges to cluster admin.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| canonical | lxd | From 4.12 (inc) to 5.0.6 (inc) |
| canonical | lxd | From 5.21.0 (inc) to 5.21.4 (inc) |
| canonical | lxd | From 6.0 (inc) to 6.7 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-915 | The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified. |