CVE-2026-34179Disclosure(canonical / lxd)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch canonical lxd systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests to /1.0/certificates/{fingerprint} for restricted TLS certificate users, allowing a remote authenticated attacker to escalate privileges to cluster admin.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-915

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • lxd

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 3 mentions (2026-04-09); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
lxd

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-04-09: 3Mentions · 2026-04-10: 1Mentions · 2026-04-12: 1Mentions · 2026-04-13: 1Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-04-13: 1Technical Details · 2026-04-09: 3Technical Details · 2026-04-12: 1Technical Details · 2026-04-13: 104-0904-1004-1204-13
Signal classification2 categories
Disclosure
466.7%
Patch
233.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-093
Disclosure2Patch1
2026-04-101
Disclosure1
2026-04-121
Disclosure1
2026-04-131
Patch1
Full discourse6 posts
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Three critical bugs CVE-2026-34177, CVE-2026-34178, CVE-2026-34179 in Canonical LXD 4.12-6.7 let authenticated users escalate to cluster admin and host root, fixed in 6.8. https://threatcluster.io/cluster/critical-privilege-escalation-vulnerabilities-in-canonical-l-66d99654

    Post summary

    Three critical privilege escalation bugs in Canonical LXD were disclosed; no PoC or exploit was cited, and the issue was patched in version 6.8.

    0000047
    149 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical privilege escalation flaw (CVE-2026-34179) affects `LXD`. An attacker could gain cluster admin by modifying a restricted TLS certificate. Review `LXD` security and certificate management practices. #LXD #Security #PrivilegeEscalation https://www.pulsepatch.io/posts/cve-2026-34179-lxd-tls-privilege-escalation

    Post summary

    The post announces a critical privilege‑escalation flaw in LXD that lets attackers gain cluster admin rights by tampering with a restricted TLS certificate, urging security reviews.

    0000043
    13 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-34179 📊 Severity: 9.1 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-34179 #CVE-2026-34179 #CVE #Critical #CyberSecurity #InfoSec https://t.co/ihXwPl1qem

    Post summary

    The tweet announces the new CVE-2026-34179 with a critical severity of 9.1 and a risk level flag, referencing the NVD detail page but providing no further technical or mitigation information.

    0000031
    123 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34179: CRITICAL] Critical security vulnerability in Canonical LXD versions 4.12 through 6.7 allows remote authenticated attackers to escalate privileges to cluster admin. Update now to stay secure!#cve,CVE-2026-34179,#cybersecurity https://cvefind.com/CVE-2026-34179

    Post summary

    The tweet warns of a critical privilege‑escalation CVE in Canonical LXD 4.12‑6.7 and urges users to apply the available update to mitigate the risk.

    00000137
    619 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-34179 In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests … https://www.cve.org/CVERecord?id=CVE-2026-34179 ----- Traducción: CVE-2026-34179 En … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑34179, detailing a missing validation in Canonical LXD’s doCertificateUpdate function, with no evidence of PoC, exploit tool, active exploitation, patch, or debunking claim.

    0000031
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34179 In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests … https://www.cve.org/CVERecord?id=CVE-2026-34179

    Post summary

    The post announces a known vulnerability in Canonical LXD, detailing the affected function and versions without providing PoC, exploits, or fixes, indicating a disclosure of technical details.

    00000143
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcanonicallxd---

Explore more