CVE-2026-9640
Last modified
CVE-2026-9640 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration.. An authenticated project operator in a restricted multi-tenant environment can bypass policy restrictions by importing a maliciously crafted instance backup containing restricted configuration keys within a snapshot. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration.. An authenticated project operator in a restricted multi-tenant environment can bypass policy restrictions by importing a maliciously crafted instance backup containing restricted configuration keys within a snapshot. When the snapshot is restored, these restricted keys are applied to the live instance without policy validation. Starting the modified instance grants the operator unauthorized host root access.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Lxd | >= 4.12, < 5.0.7 |
| Canonical | Lxd | >= 5.21.0, < 5.21.5 |
| Canonical | Lxd | >= 6.0, < 6.9 |
References
- https://github.com/canonical/lxd/pull/18301Issue Tracking, Patch
- https://github.com/canonical/lxd/pull/18303Issue Tracking, Patch
- https://github.com/canonical/lxd/pull/18304Issue Tracking, Patch
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-9640?
How severe is CVE-2026-9640?
How do I fix CVE-2026-9640?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9634A security issue exists within the Redundancy Module Configu…7
- CVE-2026-9635The WP Shortcode by MyThemeShop plugin for WordPress is vuln…6.4
- CVE-2026-9636A security issue exists within CompactLogix® 5380, ControlLo…8.2
- CVE-2026-9637A denial-of-service security issue exists in the affected Lo…8.7
- CVE-2026-9638Crypt::PBKDF2 versions before 0.261630 for Perl generate ins…7.5
- CVE-2026-9639Nil-pointer dereference in CreateCustomVolumeFromBackup in L…6.5
- CVE-2026-9641Crypt::PBKDF2 versions before 0.261630 for Perl have a weak …5.3
- CVE-2026-9642Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-9643The WP Meta SEO plugin for WordPress is vulnerable to Unauth…7.2
- CVE-2026-9644The LiveSmart Video Chat Live Video Chat plugin for WordPres…6.4
- CVE-2026-96442A code execution flaw was found in Emacs, affecting versions…7.8
- CVE-2026-96443Insufficient validation of the JDBC driver URL in Apache Dor…6.5
Are you affected by CVE-2026-9640?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
