---
id: CVE-2026-85526
title: >-
  Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on
  Linux allows an authenticated user with instance creation privileges to delete
  or replace arbitrary files and directories on the host filesystem as root via
  a …
summary: >-
  Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on
  Linux allows an authenticated user with instance creation privileges to delete
  or replace arbitrary files and directories on the host filesystem as root via
  a …
severity: critical
cvss: 9.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-22
vendor: Canonical
product: LXD
affected:
  - LXD >= 4.0.0 < 4.0.14
  - LXD >= 5.0.0 < 5.0.10
  - LXD >= 5.21.0 < 5.21.8
  - LXD >= 6.0 < 6.10
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T15:12:32.657'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85526'
references:
  - url: 'https://github.com/canonical/lxd-private/pull/103'
    label: security@ubuntu.com
  - url: 'https://github.com/canonical/lxd-private/pull/104'
    label: security@ubuntu.com
  - url: 'https://github.com/canonical/lxd-private/pull/105'
    label: security@ubuntu.com
  - url: 'https://github.com/canonical/lxd-private/pull/84'
    label: security@ubuntu.com
  - url: 'https://github.com/canonical/lxd-private/pull/87'
    label: security@ubuntu.com
  - url: 'https://github.com/canonical/lxd/security/advisories/GHSA-h85r-gjgx-g2rv'
    label: security@ubuntu.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-28T13:53:32.983935Z'
ingestedAt: '2026-09-28T14:12:02.163Z'
---

## Overview

Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvolumes[].path entry in backup/optimized_header.yaml during a btrfs optimized backup import.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
