CVE-2026-28384Critical· 9.9▾ MidnightAn improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints. This iss…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 54.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.5%
Last analysed / modified upstream
0.5% → 0.7%
An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints. This issue affected LXD from 4.12 through 6.6 and was fixed in the snap versions 5.0.6-e49d9f4 (channel 5.0/stable), 5.21.4-1374f39 (channel 5.21/stable), and 6.7-1f11451 (channel 6.0 stable). The channel 4.0/stable is not affected as it contains version 4.0.10.
lxd >= 4.12, < 5.0.6lxd >= 5.21.0, < 5.21.4lxd >= 6.0, < 6.7Upgrade past the affected range:
lxd 6.7Connected by shared product, vendor, weakness, or advisory.
CVE-2026-63298Critical· 9.9An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives
CVE-2026-66897Critical· 9.9A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root
CVE-2026-63297Critical· 9.9An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies
CVE-2026-16033High· 8.5A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation
CVE-2026-63299Critical· 9.9An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits
CVE-2026-63300Critical· 9.9An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security res…