MEDIUM 6.3 NVD
CVE-2026-86335
Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images fro
Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance import requests.
References
- https://github.com/canonical/lxd/pull/18987
- https://github.com/canonical/lxd/pull/19001
- https://github.com/canonical/lxd/pull/19002
- https://github.com/canonical/lxd/pull/19003
- https://github.com/canonical/lxd/security/advisories/GHSA-j7p3-5g2v-69j8
This medium severity vulnerability with a CVSS score of 6.3 was published on 2026-09-28 via NVD.
vulnfeed aggregates 13625 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.