Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance import requests.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to LXD versions 5.0.10, 5.21.8, 6.10 or later.
Workaround
No workaround given by the vendor.
References
History
Mon, 28 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance import requests. | |
| Title | LXD Cross-Project Private Image Theft via Unsanitized GetImageFromAnyProject Local Reuse | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-09-28T13:21:29.891Z
Reserved: 2026-09-07T08:01:22.942Z
Link: CVE-2026-86335
No data.
Status : Received
Published: 2026-09-28T14:17:20.740
Modified: 2026-09-28T14:17:20.740
Link: CVE-2026-86335
No data.
OpenCVE Enrichment
No data.
Weaknesses