CVE-2026-66898
PoC largePath Traversal in Canonical LXD Backup Import and Restore
CVE-2026-66898 is a critical path traversal flaw (CWE-22) in Canonical LXD's handling of backup archives. When a backup archive is imported or restored, LXD does not validate the instance and storage volume names embedded in the archive metadata, so names containing path traversal sequences can escape the designated restore directory. An authenticated attacker who can supply a crafted backup archive gains file read/overwrite outside the restore directory, potentially reaching sensitive host files and, given the scope-changed CVSS 9.9 rating (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H), having impact beyond the LXD component itself. Any deployment of affected LXD versions is exposed, with the highest risk in multi-tenant setups where lower-privileged or untrusted users can trigger backup imports or restores. There is no evidence of in-the-wild exploitation yet: EPSS is 0.3% (28th percentile), it is not in CISA KEV, and the only public reference is the Canonical advisory/PoC (GHSA-m857-c7gc-c984).
What to do: Upgrade LXD to the fixed release identified in Canonical's advisory (GHSA-m857-c7gc-c984) and apply the corresponding Ubuntu updates. Until patched, restrict LXD API access to trusted users and import backup archives only from trusted sources, since exploitation requires the ability to trigger a backup import or restore. Check logs for imports of third-party or untrusted archives and, where possible, verify that instance and storage volume names in archive metadata contain no path traversal sequences.
| Canonical LXD | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside the designated restore directory.
- Vendors
- canonical
- Products
- lxd
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.