CVE-2026-66897

CRITICAL CVSS 3.1: 9.9 EPSS 0.67%
Updated Sep 11, 2026
Canonical
Parameter Value
CVSS 9.9 (CRITICAL)
Affected Versions 5.0.0 — 6.9
Fixed In 4.0.13
Type CWE-23 (Relative Path Traversal), CWE-22 (Path Traversal)
Vendor Canonical
Public PoC No

A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in metadata.yaml, LXD validates the path against a confined os.Root directory handle but subsequently opens and creates the file using os.Create with an unconfined string path. This discrepancy between path resolution checks and file creation allows an attacker to escape directory confinement, overwrite root-owned host files, and achieve host root code execution.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products 4

Configuration From (including) Up to (excluding)
Canonical Lxd
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
4.0.13
Canonical Lxd
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
5.0.0 5.0.9
Canonical Lxd
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
5.1 5.21.7
Canonical Lxd
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
6.0 <= 6.9