
Three critical LXD flaws (CVE-2026-87799, CVE-2026-85185, CVE-2026-85526, CVSS up to 9.9) let an authenticated user with instance creation rights write or delete files on the host as root. All three abuse migration or btrfs backup import paths. Risk is highest on shared hosts where many users can create instances. No exploitation reported by Canonical. Fixed in 5.21.8, 5.0.10, 4.0.14 and the latest 6.x. Details: http://vulntracker.io/cves/CVE-2026-87799 #LXD #Canonical #CVE #InfoSec

