Description
Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create custom volumes in a project to copy, and so read, any custom storage volume from any other project on the server, including its snapshots and configuration. The client does this with a crafted request that sets a source volume and source.project but omits source.type.
Published: 2026-09-28
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: Unauthorized data disclosure across projects
Action: Immediate Patch
AI Analysis

Impact

An authorization flaw in Canonical LXD’s custom storage volume creation endpoint lets an authenticated client copy any custom volume from another project by sending a crafted request that sets a source volume and source.project but omits source.type. The flaw allows the attacker to read the volume’s data, snapshots, and configuration, exposing sensitive information belonging to other projects.

Affected Systems

The CNA data lists Canonical LXD as the affected product, but no specific versions are provided. The vulnerability applies to installations that expose the custom volume creation API, and the description indicates that it is present in versions 5.0.0 and later until fixed in the releases noted in the advisory.

Risk and Exploitability

The CVSS score of 7.7 indicates high severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Attack requires an authenticated client that has permission to create custom volumes in their project, a privilege that is commonly granted. Once authenticated, the exploit is straightforward: craft the request to copy the desired volume, which results in confidential data disclosure across projects.

Generated by OpenCVE AI on September 28, 2026 at 15:51 UTC.

Remediation

Vendor Solution

Upgrade to LXD versions 5.0.10, 5.21.8, 6.10 or later.


OpenCVE Recommended Actions

  • Upgrade Canonical LXD to version 5.0.10, 5.21.8, 6.10 or later as stated in the CNA
  • Review and tighten project permissions so that only administrators or trusted users can create custom volumes; deny create rights to regular users
  • Verify that volume copy attempts from non-associated projects now fail, confirming the fix and permission settings

Generated by OpenCVE AI on September 28, 2026 at 15:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Canonical
Canonical lxd
Vendors & Products Canonical
Canonical lxd

Mon, 28 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create custom volumes in a project to copy, and so read, any custom storage volume from any other project on the server, including its snapshots and configuration. The client does this with a crafted request that sets a source volume and source.project but omits source.type.
Title Incorrect authorization in LXD storage volume API allows reading volumes from other projects
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published:

Updated: 2026-09-28T16:32:28.403Z

Reserved: 2026-09-24T12:15:00.374Z

Link: CVE-2026-97335

cve-icon Vulnrichment

Updated: 2026-09-28T16:22:31.346Z

cve-icon NVD

Status : Deferred

Published: 2026-09-28T14:17:24.103

Modified: 2026-09-28T17:17:53.530

Link: CVE-2026-97335

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T16:00:03Z

Weaknesses