A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside the designated restore directory.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Upgrade to LXD version 4.0.12 or later, 5.0.4 or later, or 5.12.2 or later, or 6.0 or later.


Workaround

No workaround given by the vendor.

History

Wed, 12 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside the designated restore directory.
Title Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published:

Updated: 2026-08-12T20:07:32.889Z

Reserved: 2026-07-28T07:41:26.311Z

Link: CVE-2026-66898

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-12T21:17:39.700

Modified: 2026-08-12T21:17:39.700

Link: CVE-2026-66898

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses