CVE-2026-86335
Deferred
Deferred - Pending Action
Authorization Bypass in Canonical LXD Image Import
Vulnerability report for CVE-2026-86335, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-28
Last updated on: 2026-09-28
Assigner: Canonical Ltd.
Description
Description
Missing Authorization in imageDownload in Canonical LXD before 5.0.10,Β 5.21.8, and 6.10Β on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance import requests.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| canonical | lxd | to 5.0.10 (exc) |
| canonical | lxd | From 5.21.8 (inc) |
| canonical | lxd | From 6.10 (inc) |
| canonical | lxd | From 6.10 (inc) to 5.0.10 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |