---
id: CVE-2026-97335
title: >-
  Incorrect authorization in the custom storage volume creation endpoint in
  Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on
  Linux allows an authenticated client with permission to create custom volumes
  in a pro…
summary: >-
  Incorrect authorization in the custom storage volume creation endpoint in
  Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on
  Linux allows an authenticated client with permission to create custom volumes
  in a pro…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-863
vendor: Canonical
product: LXD
affected:
  - LXD >= 5.0.0 < 5.0.10
  - LXD >= 5.21.0 < 5.21.8
  - LXD >= 6.0 < 6.10
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T15:12:32.657'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97335'
references:
  - url: 'https://github.com/canonical/lxd/security/advisories/GHSA-p456-92fx-44xh'
    label: security@ubuntu.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T14:12:02.169Z'
---

## Overview

Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create custom volumes in a project to copy, and so read, any custom storage volume from any other project on the server, including its snapshots and configuration. The client does this with a crafted request that sets a source volume and source.project but omits source.type.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
