CRITICAL 9.9 NVD

CVE-2026-63294

A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image o

A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml file when it exists as a symbolic link. An attacker can exploit this flaw by providing a malicious archive with a symlinked backup.yaml file, causing LXD to process unconfined configuration metadata and execute arbitrary commands with root privileges.

References

Published: 2026-08-12 · Source: NVD · Feed updated: 2026-08-12
This critical severity vulnerability with a CVSS score of 9.9 was published on 2026-08-12 via NVD.

Risk Timeline

CVE Disclosed2026-08-12 · -1 days ago

Remediation Resources

vulnfeed aggregates 10542 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.