CVE-2026-66898: Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE
A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside the designated restore directory.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
LXDto a version that resolves this vulnerability.Fixed in 4.0.12 - Upgrade
Upgrade
LXDto a version that resolves this vulnerability.Fixed in 5.0.4 - Upgrade
Upgrade
LXDto a version that resolves this vulnerability.Fixed in 5.12.2 - Upgrade
Upgrade
LXDto a version that resolves this vulnerability.Fixed in 6.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66898?
CVE-2026-66898 has a severity rating of critical with a score of 9.9.
What impact does CVE-2026-66898 have on systems?
CVE-2026-66898 allows an attacker to conduct path traversal attacks leading to root file write and remote code execution.
How do I fix CVE-2026-66898?
To fix CVE-2026-66898, ensure that you are using the latest version of Canonical LXD that addresses this vulnerability.
What systems are affected by CVE-2026-66898?
CVE-2026-66898 affects Canonical LXD versions prior to the patch that resolves this path traversal vulnerability.
How can an attacker exploit CVE-2026-66898?
An attacker can exploit CVE-2026-66898 by manipulating file system paths in backup tarball restore operations without proper validation of instance names.