CVE-2026-87799

LOWCVSS 9.9 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a project, or a malicious migration source server, to write attacker-controlled files to arbitrary paths on the target host as root, leading to full host compromise. The attacker does this with a crafted rsync or btrfs send stream that plants a symlink in the transferred volume, such as rootfs or root.img, and then writes through it.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 2 mentions on most recent observed day (2026-09-29)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-09-28: 1Mentions · 2026-09-29: 209-2809-29
Referenced assets2 URLs
Full discourse3 posts
  • Daily CyberSecurity@Daily_CyberSec

    Three critical LXD vulnerabilities, including CVE-2026-87799 (CVSS 9.9), let container users write files as root on the host. Patch to 5.21.8 or 6.10. #LXD #LXDVulnerabilities #Canonical #ContainerSecurity #btrfs #PathTraversal #LinuxSecurity #PatchNow https://securityonline.info/lxd-vulnerabilities-host-root/

    01111987
    13.0K followersView on X
  • VulnTracker@vuln_tracker

    Three critical LXD flaws (CVE-2026-87799, CVE-2026-85185, CVE-2026-85526, CVSS up to 9.9) let an authenticated user with instance creation rights write or delete files on the host as root. All three abuse migration or btrfs backup import paths. Risk is highest on shared hosts where many users can create instances. No exploitation reported by Canonical. Fixed in 5.21.8, 5.0.10, 4.0.14 and the latest 6.x. Details: http://vulntracker.io/cves/CVE-2026-87799 #LXD #Canonical #CVE #InfoSec

    01021245
    781 followersView on X
  • Atlas Threat Monitoring@ThreatAtlas

    Unpatched vulnerabilities don't stay hidden on our atlas. #CVE CRITICAL VULNERABILITY DETECTED CVE ID → CVE-2026-87799 Vendor → Unknown Severity → Critical — CVSS 9.9 Product → Unknown Date → 2026-09-28 A critical vulnerability (Link Following) has been disclosed affecting Unknown. Patch immediately. Powered by @Brandefense #ThreatIntel #CyberSecurity #CVE #Unknown

    0000040
    420 followersView on X

Explore more