Description
Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine to write attacker-controlled files or directory trees to arbitrary paths on the client host, with the operator's privileges. The attacker does this by using a modified lxd-agent that returns inconsistent SFTP directory listings and Lstat results.
Published: 2026-09-28
Score: 5.8 Medium
EPSS: n/a
KEV: No
Impact: Privilege Escalation to Host
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from improper link resolution in the recursive file pull feature of the LXD CLI client. An attacker who has obtained root access inside a virtual machine can supply a modified lxd-agent that presents inconsistent directory listings and stat results. When the client performs a pull operation, it resolves file paths without proper sanitization, allowing the attacker to write executable code or modify system files anywhere on the host machine. As a result, an attacker can escape the isolation provided by the virtual environment and compromise the host system, potentially leading to full system takeover.

Affected Systems

Canonical LXD releases from 4.0.2 through 6.9 are affected. The vulnerability is fixed in LXD 4.0.14, 5.0.10, and 5.21.8 and later. The affected environment is a Linux host running the LXD client interacting with virtual machines.

Risk and Exploitability

The CVSS score of 5.8 classifies this issue as moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector requires an attacker to already have root privileges inside a VM and to supply a tampered lxd-agent; therefore, it is an exploited privilege escalation path rather than a publicly reachable network attack. The lack of remote exploitation guards and the need for internal VM compromise somewhat reduce immediate risk but do not eliminate it.

Generated by OpenCVE AI on September 28, 2026 at 15:25 UTC.

Remediation

Vendor Solution

Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8 or later.


OpenCVE Recommended Actions

  • Upgrade to LXD 4.0.14, 5.0.10, 5.21.8 or later to apply the vendor patch.
  • Verify that all lxd-agent binaries used by virtual machines come from Canonical’s official distribution and have not been modified.
  • If a patch cannot be applied immediately, isolate virtual machines with strict network segmentation and monitor host files for unexpected writes as a temporary safeguard.

Generated by OpenCVE AI on September 28, 2026 at 15:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Canonical
Canonical lxd
Vendors & Products Canonical
Canonical lxd

Mon, 28 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine to write attacker-controlled files or directory trees to arbitrary paths on the client host, with the operator's privileges. The attacker does this by using a modified lxd-agent that returns inconsistent SFTP directory listings and Lstat results.
Title LXD client recursive file pull allows directory escape via malicious VM agent
Weaknesses CWE-59
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published:

Updated: 2026-09-28T16:32:28.148Z

Reserved: 2026-09-09T10:00:46.383Z

Link: CVE-2026-87798

cve-icon Vulnrichment

Updated: 2026-09-28T16:22:28.362Z

cve-icon NVD

Status : Deferred

Published: 2026-09-28T14:17:21.290

Modified: 2026-09-28T17:17:51.673

Link: CVE-2026-87798

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T15:30:02Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')