CVE-2026-66897Disclosure(canonical / lxd)

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch canonical lxd systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in metadata.yaml, LXD validates the path against a confined os.Root directory handle but subsequently opens and creates the file using os.Create with an unconfined string path. This discrepancy between path resolution checks and file creation allows an attacker to escape directory confinement, overwrite root-owned host files, and achieve host root code execution.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-23

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • lxd

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-24); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
lxd

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-24: 2Mentions · 2026-08-25: 1Patch / Workaround · 2026-08-24: 1Patch / Workaround · 2026-08-25: 1Technical Details · 2026-08-24: 2Technical Details · 2026-08-25: 108-2408-25
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-242
Disclosure1General1
2026-08-251
Patch1
Full discourse3 posts
  • Sami Laiho@samilaiho
    Patch

    Instance template path traversal allows arbitrary host file write as root URL: https://nvd.nist.gov/vuln/detail/CVE-2026-66897 Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.9

    Post summary

    CVE-2026-66897 is a critical path traversal vulnerability allowing root-level file writes, and an official fix has already been released.

    01000912
    30.6K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - LXD Host Root via Template Path Traversal (CVE-2026-66897) A flaw in LXD's template processing allows a standard ../ traversal to escape root confinement. Attackers launching a crafted image or editing a container can overwrite arbitrary host files, leading to a full container escape and host root RCE. 👉 Affected: Canonical LXD versions prior to 4.0.13, 5.0.9, 5.21.7, and 6.10 | Upgrade to: 4.0.13, 5.0.9, 5.21.7, 6.10

    Post summary

    The announcement discloses a critical template path traversal vulnerability in LXD that permits host root RCE, and it includes upgrade guidance to mitigate the issue.

    0000081
    294 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-66897 A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to ove… https://www.cve.org/CVERecord?id=CVE-2026-66897

    Post summary

    The text provides a brief vulnerability description for CVE-2026-66897, noting a path traversal issue in LXD's template processing but offers no PoC, exploit, or mitigation details.

    000001.2K
    58.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcanonicallxd---

Explore more