CVE-2026-87798: LXD client recursive file pull allows directory escape via malicious VM agent

Published Sep 28, 2026
·
Updated

Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine to write attacker-controlled files or directory trees to arbitrary paths on the client host, with the operator's privileges. The attacker does this by using a modified lxd-agent that returns inconsistent SFTP directory listings and Lstat results.

Affected Software

1 affected component
Canonical LXD>=4.0.2<=6.9

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Canonical LXD to a version that resolves this vulnerability.

    Fixed in 4.0.14
  2. Upgrade

    Upgrade Canonical LXD to a version that resolves this vulnerability.

    Fixed in 5.0.10
  3. Upgrade

    Upgrade Canonical LXD to a version that resolves this vulnerability.

    Fixed in 5.21.8

Event History

Sep 28, 2026
CVE Published
via MITRE·01:22 PM
Data Sourced
via MITRE·01:22 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Linux operators using an affected LXD CLI version are exposed when they recursively pull files from a virtual machine whose in-guest agent is controlled by an attacker. The attacker needs root access inside that VM to replace or modify the lxd-agent behavior.

2

What interaction is required for exploitation?

An operator must use the LXD CLI recursive file pull feature against the malicious VM. The attack relies on the agent returning inconsistent SFTP directory-listing and Lstat results during that pull.

3

What is the impact on the client host?

A successful attack can cause attacker-controlled files or directory trees to be written to arbitrary paths on the client host. Writes occur with the privileges of the operator running the LXD CLI.

4

Which versions contain fixes?

Canonical identifies fixes in LXD 4.0.14, 5.0.10, and 5.21.8. The affected version ranges are 4.0.2 through 6.9.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203