Description
Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance import requests.
Published: 2026-09-28
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized access to private images across projects
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a missing authorization check in the imageDownload operation that allows a client bound to one project to download images from another project when the images share the same local fingerprint. This flaw constitutes an incomplete permission check (CWE-862) and enables the theft of private image data. An attacker who can invoke the image or instance import API on the host can obtain binaries or configuration files that belong solely to a different project, potentially revealing sensitive configuration or application artifacts.

Affected Systems

Canonical LXD containers before versions 5.0.10, 5.21.8, and 6.10 running on Linux are affected. Users operating LXD with multiple projects on the same host may unintentionally expose private images if they share common fingerprints during imports.

Risk and Exploitability

The CVSS score of 6.3 indicates a medium security impact. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog, suggesting the exploitation likelihood is currently unclear. The vulnerability requires local access to the LXD server endpoint; the client must be authenticated under its own project. Thus, the attack vector is inferred to be local and limited to the host environment.

Generated by OpenCVE AI on September 28, 2026 at 15:29 UTC.

Remediation

Vendor Solution

Upgrade to LXD versions 5.0.10, 5.21.8, 6.10 or later.


OpenCVE Recommended Actions

  • Upgrade to LXD 5.0.10, 5.21.8, 6.10, or later as provided by the vendor.
  • If an upgrade cannot be performed immediately, isolate image storage so that projects use distinct image pools or enforce strict project‑specific image import policies to prevent reuse of fingerprints across projects.
  • Review and tighten project roles so that only users with explicit image‑download privileges can initiate imports, and ensure that project boundaries are respected in the LXD configuration.

Generated by OpenCVE AI on September 28, 2026 at 15:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Canonical
Canonical lxd
Vendors & Products Canonical
Canonical lxd

Mon, 28 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance import requests.
Title LXD Cross-Project Private Image Theft via Unsanitized GetImageFromAnyProject Local Reuse
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published:

Updated: 2026-09-28T16:32:28.655Z

Reserved: 2026-09-07T08:01:22.942Z

Link: CVE-2026-86335

cve-icon Vulnrichment

Updated: 2026-09-28T16:22:33.924Z

cve-icon NVD

Status : Deferred

Published: 2026-09-28T14:17:20.740

Modified: 2026-09-28T17:17:51.407

Link: CVE-2026-86335

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T15:45:02Z

Weaknesses