CVE-2026-16033
Last modified
CVE-2026-16033 is a high-severity vulnerability rated 8.5/10 on the CVSS scale. A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the instance templates directory (specifically affecting virtual machine / QEMU driver execution paths). EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the instance templates directory (specifically affecting virtual machine / QEMU driver execution paths). An attacker can exploit this flaw by providing a crafted image archive with malicious template directives containing path traversal sequences, causing LXD to access or write files outside the intended template directory on the host system.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Lxd | >= 4.0.0, < 4.0.12 |
| Canonical | Lxd | >= 5.0.0, < 5.0.7 |
References
- https://github.com/canonical/lxd/security/advisories/GHSA-9hcm-hxh5-7xxhVendor Advisory, Exploit
- https://github.com/canonical/lxd/security/advisories/GHSA-9hcm-hxh5-7xxhVendor Advisory, Exploit
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-16033?
How severe is CVE-2026-16033?
How do I fix CVE-2026-16033?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-16025Improper validation of specified quantity in input vulnerabi…7.5
- CVE-2026-16027Server-Side request forgery (SSRF) vulnerability in Revenue …5.4
- CVE-2026-16028Protocol::HTTP2 versions before 1.14 for Perl allow memory e…7.5
- CVE-2026-1603An authentication bypass in Ivanti Endpoint Manager before v…7.5
- CVE-2026-16030The MStore API WordPress plugin before 4.21.0 does not corr…8.1
- CVE-2026-16032The LWS Optimize WordPress plugin before 4.1.2 does not pro…6.1
- CVE-2026-16035The miniOrange 2FA WordPress plugin before 6.2.7 does not r…4.3
- CVE-2026-16036The miniOrange 2FA WordPress plugin before 6.2.7 does not b…7.5
- CVE-2026-16037Observable timing discrepancy vulnerability in PayTR Payment…7.5
- CVE-2026-16038The MStore API WordPress plugin before 4.21.0 does not veri…9.1
- CVE-2026-16039The MStore API WordPress plugin before 4.21.0 does not rest…6.5
- CVE-2026-16041The MStore API WordPress plugin before 4.21.0 does not perf…7.5
Are you affected by CVE-2026-16033?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
