CVE-2026-85185
Last modified
CVE-2026-85185 is a critical-severity vulnerability rated 9.6/10 on the CVSS scale. Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is btrfs, the client can also place attacker-controlled content at arbitrary host paths, leading to full host compromise.
Description
Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is btrfs, the client can also place attacker-controlled content at arbitrary host paths, leading to full host compromise. The client does this with a crafted subvolume path containing ../ sequences, sent in either of two ways: in the optimized_header.yaml of an optimized btrfs backup, or in the btrfs migration header sent by a malicious migration source.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Canonical | LXD | >= 4.0.2, < 4.0.14; >= 5.0.0, < 5.0.10; >= 5.21.0, < 5.21.8; >= 6.0, < 6.10 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-85185?
How severe is CVE-2026-85185?
How do I fix CVE-2026-85185?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-8518Use after free in Blink in Google Chrome prior to 148.0.7778…8.8
- CVE-2026-85180Ollama fails to validate redirect destinations when pulling …7.5
- CVE-2026-85181CAT uses Java String.hashCode as the sole integrity check fo…9.8
- CVE-2026-85182vhr through commit 03abbd3 fails to verify that the account …7.5
- CVE-2026-85183Taipy configures its socket.io server with wildcard CORS ori…9.3
- CVE-2026-85184@fastify/middie versions >= 9.1.0 and before 9.3.4 decide wh…9.1
- CVE-2026-85186A weakness has been identified in itsourcecode Online Medici…6.3
- CVE-2026-85187A security vulnerability has been detected in itsourcecode O…7.3
- CVE-2026-85188Joomla Extension - regularlabs.com - Database data disclosur…6.9
- CVE-2026-85189Joomla Extension - regularlabs.com - Privileged stored XSS v…7.5
- CVE-2026-8519Integer overflow in ANGLE in Google Chrome on Windows prior …8.8
- CVE-2026-85190Joomla Extension - regularlabs.com - Privileged stored XSS v…7.5
Are you affected by CVE-2026-85185?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
