CVE-2026-16033

HIGH CVSS 3.1: 8.5 EPSS 0.35%
Updated Sep 11, 2026
Canonical
Parameter Value
CVSS 8.5 (HIGH)
Affected Versions 4.0.0 — 5.0.7
Fixed In 4.0.12
Type CWE-22 (Path Traversal)
Vendor Canonical
Public PoC No

A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the instance templates directory (specifically affecting virtual machine / QEMU driver execution paths). An attacker can exploit this flaw by providing a crafted image archive with malicious template directives containing path traversal sequences, causing LXD to access or write files outside the intended template directory on the host system.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 2

Configuration From (including) Up to (excluding)
Canonical Lxd
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
4.0.0 4.0.12
Canonical Lxd
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
5.0.0 5.0.7