CVE-2026-86334
Last modified
CVE-2026-86334 is a medium-severity vulnerability rated 4.2/10 on the CVSS scale. Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite arbitrary local files and execute code on the client system via a crafted Content-Disposition header filename parameter during unified image export or copy operations into a local directory target..
Description
Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite arbitrary local files and execute code on the client system via a crafted Content-Disposition header filename parameter during unified image export or copy operations into a local directory target.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Canonical | LXD | >= 4.0.2, < 4.0.14; >= 5.0.0, < 5.0.10; >= 5.21.0, < 5.21.8; >= 6.0, < 6.10 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-86334?
How severe is CVE-2026-86334?
How do I fix CVE-2026-86334?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-8632A potential security vulnerability has been identified in th…7.8
- CVE-2026-86320A flaw was found in flatpak-builder where Git hooks are not …7.8
- CVE-2026-86321A vulnerability was found in java-json-tools jackson-coreuti…5.3
- CVE-2026-8633IBM Web Server Plug-ins for WebSphere Application Server and…9.8
- CVE-2026-86330An OS command injection flaw was found in the set_hostname_i…7.2
- CVE-2026-86332A flaw was found in odh-dashboard in Red Hat OpenShift AI. T…6.5
- CVE-2026-86335Missing Authorization in imageDownload in Canonical LXD befo…6.3
- CVE-2026-86338Ash field_policies are documented to protect against filter-…6
- CVE-2026-8634Crabbox prior to v0.12.0 contains an environment variable ex…9.3
- CVE-2026-86341GitLab has remediated an issue in GitLab EE affecting all ve…4.4
- CVE-2026-86342Affected versions of MISP contain improper authorization che…4.3
- CVE-2026-86347Affected versions of MISP allow any authenticated user to ac…6.5
Are you affected by CVE-2026-86334?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
