CVE-2026-34178Disclosure(canonical / lxd)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch canonical lxd systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supplied tar archive but creates the instance from backup/container/backup.yaml, a separate file in the same archive that is never checked against project restrictions. An authenticated remote attacker with instance-creation permission in a restricted project can craft a backup archive where backup.yaml carries restricted settings such as security.privileged=true or raw.lxc directives, bypassing all project restriction enforcement and allowing full host compromise.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • lxd

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-04-09); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
lxd

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-04-09: 3Mentions · 2026-04-10: 1Mentions · 2026-04-12: 1Mentions · 2026-04-13: 1Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-04-13: 1Technical Details · 2026-04-09: 3Technical Details · 2026-04-12: 1Technical Details · 2026-04-13: 104-0904-1004-1204-13
Signal classification3 categories
Disclosure
466.7%
Patch
116.7%
General
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-093
Disclosure2Patch1
2026-04-101
General1
2026-04-121
Disclosure1
2026-04-131
Disclosure1
Full discourse6 posts
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Three critical bugs CVE-2026-34177, CVE-2026-34178, CVE-2026-34179 in Canonical LXD 4.12-6.7 let authenticated users escalate to cluster admin and host root, fixed in 6.8. https://threatcluster.io/cluster/critical-privilege-escalation-vulnerabilities-in-canonical-l-66d99654

    Post summary

    The text announces three critical privilege‑escalation CVEs in Canonical LXD, notes the bug details, and indicates that the issues are fixed in the upcoming 6.8 release.

    0000047
    149 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A project restriction bypass vulnerability (CVE-2026-34178) affects `LXD` through crafted backup import. This could lead to unauthorized resource access. #LXD #ContainerSecurity #InfoSec https://www.pulsepatch.io/posts/cve-2026-34178-lxd-restriction-bypass

    Post summary

    The brief post announces CVE-2026-34178, a project restriction bypass in LXD that can be triggered through crafted backup imports and may allow unauthorized resource access, with no PoC, exploit, patch, or active exploitation details provided.

    0000044
    13 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-34178 📊 Severity: 9.1 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-34178 #CVE-2026-34178 #CVE #Critical #CyberSecurity #InfoSec https://t.co/MvUYyvcSMW

    Post summary

    The tweet announces a new CVE with severity information but provides no technical depth, proofs of concept, exploitation details, or remediation guidance.

    0000033
    123 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34178: CRITICAL] Vulnerability in Canonical LXD <6.8 allows attackers to bypass project restrictions, gaining full host compromise. Update to version 6.8 for enhanced security.#cve,CVE-2026-34178,#cybersecurity https://cvefind.com/CVE-2026-34178

    Post summary

    A critical vulnerability (CVE‑2026‑34178) in Canonical LXD versions below 6.8 allows attackers to bypass project restrictions and fully compromise the host; the remediation is to upgrade to the patched 6.8 release.

    00000136
    619 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-34178 In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supplied tar archive but creates the instance from… https://www.cve.org/CVERecord?id=CVE-2026-34178 ----- Traducción: CVE-2026-34178 En … http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑34178 in Canonical LXD <6.8, describing a backup import validation issue and linking to the official CVE record.

    0000030
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34178 In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supplied tar archive but creates the instance from… https://www.cve.org/CVERecord?id=CVE-2026-34178

    Post summary

    The message announces a CVE‑2026‑34178 in Canonical LXD involving improper validation during backup import, but offers no PoC, exploit code, active exploitation evidence, or patch details.

    00000187
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcanonicallxd---

Explore more