CVE-2026-86334 MEDIUM

CVE-2026-86334: CLI Path Traversal via Content-Disposition in LXD Image Export/Copy

Vendor Canonical
Product LXD
Weakness CWE-22 · Path traversal
Published September 28, 2026
Last update September 28, 2026

CVSS base score

4.2/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L

What the vulnerability does

01Description

Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite arbitrary local files and execute code on the client system via a crafted Content-Disposition header filename parameter during unified image export or copy operations into a local directory target.

Key dates

02Disclosure timeline

September 28, 2026 CVE published
September 28, 2026 Record updated

Related vulnerabilities

04Related CVE