VulnSea

Canonical has 31 CVEs on record between 2024 and 2026. Disclosure cadence is accelerating: 18 in the last 90 days against 7 in the 90 before. The busiest recent month was August 2026 with 11. The median CVSS is 9.1 (critical), with 16 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-22 (6) and CWE-863 (6). Most affected products: LXD (22), github.com/canonical/lxd (7), github.com/canonical/microceph/microceph (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
9.1
Publish → KEV
—
Last 90 days
18 prev 7

Products

  • LXD 22
  • github.com/canonical/lxd 7
  • github.com/canonical/microceph/microceph 1
  • github.com/canonical/pebble 1
31
Total CVEs
16
Critical
0
CISA KEV
0
Exploited

Canonical vulnerabilities

CVEs affecting Canonical, newest first. Open any entry for full detail, references, and exploit status.

31 CVEsRSS

CVE-2026-86334Medium· 4.2
today

Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite arbitr…

Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite arbitr…

▾ SunlitCanonical · LXDvia NVD
CVE-2026-86335Medium· 6.3
today

Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance import …

Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance import …

▾ SunlitCanonical · LXDvia NVD
CVE-2026-85185Critical· 9.6
today

Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary …

Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary …

▾ MidnightCanonical · LXDvia NVD
CVE-2026-97335High· 7.7
today

Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create custom volumes in a pro…

Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create custom volumes in a pro…

▾ TwilightCanonical · LXDvia NVD
CVE-2026-87799Critical· 9.9
today

Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a pr…

Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a pr…

▾ MidnightCanonical · LXDvia NVD
CVE-2026-87798Medium· 5.8
today

Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine to wri…

Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine to wri…

▾ SunlitCanonical · LXDvia NVD
CVE-2026-85526Critical· 9.9PoC
today

Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a …

Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a …

▾ AbyssalCanonical · LXDvia NVD
CVE-2026-66897Critical· 9.9
1mo ago

A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root

A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing targ…

▾ Midnightcanonical · lxdEPSS 0.72%via NVD
CVE-2026-63297Critical· 9.9PoC
1mo ago

An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies

An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a tar…

▾ Abyssalcanonical · lxdEPSS 0.34%via NVD
CVE-2026-16033High· 8.5
1mo ago

A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation

A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from es…

▾ Twilightcanonical · lxdEPSS 0.35%via NVD
CVE-2026-66898Critical· 9.9
1mo ago

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names c…

▾ Midnightcanonical · lxdEPSS 0.59%via NVD
CVE-2026-63300Critical· 9.9
1mo ago

An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security res…

An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security res…

▾ Midnightcanonical · lxdEPSS 0.54%via NVD
CVE-2026-63299Critical· 9.9
1mo ago

An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits

An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations: the storagePoolVolumeTypePostMove f…

▾ Midnightcanonical · lxdEPSS 0.59%via NVD
CVE-2026-63298Critical· 9.9
1mo ago

An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives

An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidi…

▾ Midnightcanonical · lxdEPSS 0.69%via NVD
CVE-2026-63296Critical· 9.9
1mo ago

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without va…

▾ Midnightcanonical · lxdEPSS 0.44%via NVD
CVE-2026-63295Medium· 4.3
1mo ago

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as enforcing restricted.…

▾ Sunlitcanonical · lxdEPSS 0.35%via NVD
CVE-2026-63294Critical· 9.9
1mo ago

A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system

A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml…

▾ Midnightcanonical · lxdEPSS 0.88%via NVD
CVE-2026-62420Critical· 9.9
1mo ago

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member vi…

▾ Midnightcanonical · lxdEPSS 0.54%via NVD
CVE-2026-9640High· 7.2
3mo ago

A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration.

A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration.. An authenticated project operator i…

▾ Twilightcanonical · lxdEPSS 0.63%via NVD
CVE-2026-9639Medium· 6.5
3mo ago

Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volum…

Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volum…

▾ Sunlitcanonical · lxdEPSS 0.55%via NVD
CVE-2026-12411High· 8.4
3mo ago

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when securi…

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when securi…

▾ Twilightcanonical · lxdEPSS 0.29%via NVD
CVE-2026-10720Medium
3mo ago

Canonical MicroCeph: path traversal issue in the remote-import AP

Canonical MicroCeph: path traversal issue in the remote-import AP

▾ Sunlitcanonical · github.com/canonical/microceph/microcephEPSS 0.30%via GHSA
CVE-2026-34178Critical· 9.1
5mo ago

LXD: Importing a crafted backup leads to project restriction bypass

LXD: Importing a crafted backup leads to project restriction bypass

▾ Midnightcanonical · github.com/canonical/lxdEPSS 0.68%via OSV
CVE-2026-34177Critical· 9.1
5mo ago

LXD: VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf

LXD: VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf

▾ Midnightcanonical · github.com/canonical/lxdEPSS 0.61%via OSV
CVE-2026-34179Critical· 9.1
5mo ago

LXD: Update of type field in restricted TLS certificate allows privilege escalation to cluster admin

LXD: Update of type field in restricted TLS certificate allows privilege escalation to cluster admin

▾ Midnightcanonical · github.com/canonical/lxdEPSS 0.42%via OSV
CVE-2026-28384Critical· 9.9
6mo ago

An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints

An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints. This iss…

▾ Midnightcanonical · lxdEPSS 0.86%via NVD
CVE-2025-54286High· 8.3
12mo ago

Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI

Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI

▾ Twilightcanonical · github.com/canonical/lxdEPSS 0.13%via OSV
CVE-2025-54288Medium· 4.1
12mo ago

Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server

Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server

▾ Sunlitcanonical · github.com/canonical/lxdEPSS 0.35%via OSV
CVE-2025-54293Medium· 6.5
12mo ago

Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function

Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function

▾ Sunlitcanonical · github.com/canonical/lxdEPSS 0.58%via OSV
CVE-2025-54289Medium· 6.8
12mo ago

Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API

Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API

▾ Sunlitcanonical · github.com/canonical/lxdEPSS 0.21%via OSV
Canonical vulnerabilities (CVEs) · VulnSea