CVE-2026-87799
Deferred Deferred - Pending Action

Improper Link Resolution in Canonical LXD

Vulnerability report for CVE-2026-87799, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: Canonical Ltd.

Description

Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a project, or a malicious migration source server, to write attacker-controlled files to arbitrary paths on the target host as root, leading to full host compromise. The attacker does this with a crafted rsync or btrfs send stream that plants a symlink in the transferred volume, such as rootfs or root.img, and then writes through it.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
canonical lxd From 4.0.14 (inc)
canonical lxd From 5.0.10 (inc)
canonical lxd From 5.21.8 (inc)
canonical lxd From 6.10 (inc)
canonical lxd to 7.3.0 (exc)
canonical lxd 4.0.14
canonical lxd 5.0.10
canonical lxd 5.21.8
canonical lxd 6.10

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-59 The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-87799 is a critical arbitrary file write vulnerability in Canonical LXD versions 4.0 and later. It occurs during migration operations when receiving an instance or custom storage volume. The issue allows an authenticated client or malicious migration source to plant a symlink in the transferred volume, which can then be used to write attacker-controlled files to arbitrary paths on the target host as root, leading to full host compromise.

Detection Guidance

To detect this vulnerability, check the version of LXD installed on your system. Run: lxd --version. If your version is 4.0, 5.0, 5.21, or 6.10 and below the respective patched versions (4.0.14, 5.0.10, 5.21.8, 6.10), your system is vulnerable.

Impact Analysis

This vulnerability allows an attacker with low privileges to gain root access on the host system, potentially leading to full compromise of the host. It can be exploited by creating instances or volumes in a project or by tricking a migration source server into sending malicious data. The impact includes loss of confidentiality, integrity, and availability of the host system.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements such as GDPR and HIPAA. Full host compromise may result in data breaches, unauthorized data access, or destruction, which are critical violations of these regulations.

Mitigation Strategies

Immediately upgrade LXD to a patched version: 4.0.14, 5.0.10, 5.21.8, or 6.10 or later. Avoid migrating instances or volumes from untrusted sources. Restrict instance and volume creation permissions to trusted clients only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87799. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart