{"id":"CVE-2026-86334","title":"Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite arbitr…","summary":"Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite arbitr…","severity":"medium","cvss":4.2,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","cwe":["CWE-22"],"vendor":"Canonical","product":"LXD","affected":["LXD >= 4.0.2 < 4.0.14","LXD >= 5.0.0 < 5.0.10","LXD >= 5.21.0 < 5.21.8","LXD >= 6.0 < 6.10"],"published":"2026-09-28","updated":"2026-09-28","sourceUpdated":"2026-09-28T15:12:32.657","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86334","references":[{"url":"https://github.com/canonical/lxd/pull/18940","label":"security@ubuntu.com"},{"url":"https://github.com/canonical/lxd/pull/18974","label":"security@ubuntu.com"},{"url":"https://github.com/canonical/lxd/pull/18975","label":"security@ubuntu.com"},{"url":"https://github.com/canonical/lxd/pull/18976","label":"security@ubuntu.com"},{"url":"https://github.com/canonical/lxd/pull/18977","label":"security@ubuntu.com"},{"url":"https://github.com/canonical/lxd/security/advisories/GHSA-g4cm-f533-78hq","label":"security@ubuntu.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-28T14:12:02.171Z","slug":"CVE-2026-86334","body":"## Overview\n\nPath traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite arbitrary local files and execute code on the client system via a crafted Content-Disposition header filename parameter during unified image export or copy operations into a local directory target.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":23,"depthScoreParts":{"impact":23.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}