CVE-2026-86335
Deferred Deferred - Pending Action

Authorization Bypass in Canonical LXD Image Import

Vulnerability report for CVE-2026-86335, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: Canonical Ltd.

Description

Missing Authorization in imageDownload in Canonical LXD before 5.0.10,Β 5.21.8, and 6.10Β on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance import requests.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
canonical lxd to 5.0.10 (exc)
canonical lxd From 5.21.8 (inc)
canonical lxd From 6.10 (inc)
canonical lxd From 6.10 (inc) to 5.0.10 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-86335 is a missing authorization vulnerability in Canonical LXD before versions 5.0.10, 5.21.8, and 6.10. It allows a project-restricted client with limited permissions to access private images from other projects by reusing a local image fingerprint during import requests. The vulnerability bypasses project isolation by exploiting the imageDownload function's lack of proper permission checks.

Detection Guidance

To detect CVE-2026-86335, check LXD logs for unauthorized image imports across projects. Look for instances where a project-restricted client accesses private images using a known fingerprint. Commands like 'lxc image list --all-projects' and 'journalctl -u lxd' may reveal suspicious activity. Ensure no unauthorized image reuse occurs between projects.

Impact Analysis

An attacker with restricted access can import private images from other projects into their own, gaining unauthorized access to sensitive data. They can view, export, or launch instances from these images. The attack requires knowledge of the target image's 64-hex fingerprint, which may be obtained through logs or backups.

Compliance Impact

This vulnerability could lead to unauthorized access to private data, violating confidentiality requirements in GDPR and HIPAA. It undermines data protection measures by allowing unauthorized users to access sensitive information, potentially resulting in compliance breaches and legal consequences.

Mitigation Strategies

Upgrade LXD to versions 5.0.10, 5.21.8, or 6.10 or later. Verify the fix by checking that image reuse is restricted to cached images with identical sources. Review project permissions to ensure only authorized users can access private images. Monitor logs for any unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86335. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart