{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-86334","assignerOrgId":"cc1ad9ee-3454-478d-9317-d3e869d708bc","state":"PUBLISHED","assignerShortName":"canonical","dateReserved":"2026-09-07T08:01:22.941Z","datePublished":"2026-09-28T13:21:15.612Z","dateUpdated":"2026-09-28T17:56:11.126Z"},"containers":{"cna":{"title":"CLI Path Traversal via Content-Disposition in LXD Image Export/Copy","datePublic":"2026-09-25T03:00:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-22","description":"CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-126","descriptions":[{"lang":"en","value":"CAPEC-126 Path Traversal"}]}],"affected":[{"vendor":"Canonical","product":"LXD","platforms":["Linux"],"packageName":"LXD","repo":"https://github.com/canonical/lxd","versions":[{"status":"affected","version":"4.0.2","lessThan":"4.0.14","versionType":"semver"},{"status":"affected","version":"5.0.0","lessThan":"5.0.10","versionType":"semver"},{"status":"affected","version":"5.21.0","lessThan":"5.21.8","versionType":"semver"},{"status":"affected","version":"6.0","lessThan":"6.10","versionType":"semver"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite arbitrary local files and execute code on the client system via a crafted Content-Disposition header filename parameter during unified image export or copy operations into a local directory target."}],"references":[{"url":"https://github.com/canonical/lxd/security/advisories/GHSA-g4cm-f533-78hq","tags":["vendor-advisory","issue-tracking"]},{"url":"https://github.com/canonical/lxd/pull/18977","tags":["patch"]},{"url":"https://github.com/canonical/lxd/pull/18976","tags":["patch"]},{"url":"https://github.com/canonical/lxd/pull/18974","tags":["patch"]},{"url":"https://github.com/canonical/lxd/pull/18975","tags":["patch"]},{"url":"https://github.com/canonical/lxd/pull/18940","tags":["patch"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW","baseSeverity":"MEDIUM","baseScore":4.2,"vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L"}}],"solutions":[{"lang":"en","value":"Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8, 6.10 or later."}],"source":{"discovery":"UNKNOWN"},"providerMetadata":{"orgId":"cc1ad9ee-3454-478d-9317-d3e869d708bc","shortName":"canonical","dateUpdated":"2026-09-28T13:21:15.612Z"}},"adp":[{"references":[{"url":"https://github.com/canonical/lxd/security/advisories/GHSA-g4cm-f533-78hq","tags":["exploit"]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-28T17:55:41.286474Z","id":"CVE-2026-86334","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-28T17:56:11.126Z"}}]}}