CVE-2026-63294(canonical / lxd)

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml file when it exists as a symbolic link. An attacker can exploit this flaw by providing a malicious archive with a symlinked backup.yaml file, causing LXD to process unconfined configuration metadata and execute arbitrary commands with root privileges.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • lxd

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
lxd

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-16: 109-16
Full discourse1 post
  • DFIR Lab@DFIR_Lab

    🚨 CRITICAL: CVE-2026-63294 (CVSS 9.9) - LXD link following vulnerability enables root command execution on host systems. Attackers exploit symlinked backup.yaml in malicious archives. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel #DFIR https://t.co/VG5FgmBPbl

    0000036
    129 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcanonicallxd---

Explore more