CVE-2026-97335: Incorrect authorization in LXD storage volume API allows reading volumes from other projects
Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create custom volumes in a project to copy, and so read, any custom storage volume from any other project on the server, including its snapshots and configuration. The client does this with a crafted request that sets a source volume and source.project but omits source.type.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Canonical LXDto a version that resolves this vulnerability.Fixed in 5.0.10 - Upgrade
Upgrade
Canonical LXDto a version that resolves this vulnerability.Fixed in 5.21.8 - Upgrade
Upgrade
Canonical LXDto a version that resolves this vulnerability.Fixed in 6.10
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated LXD client that has permission to create custom storage volumes in any project can exploit it. The client does not need permission to access the project that owns the source volume.
What data can be exposed?
An attacker can copy and read custom storage volumes belonging to other projects on the same LXD server. This includes the volumes' snapshots and configuration.
What request condition triggers the authorization bypass?
The custom volume creation request must specify a source volume and source.project while omitting source.type. This causes the source volume authorization check to be handled incorrectly.
Which releases contain fixes?
The issue is fixed in LXD 5.0.10, 5.21.8, and 6.10. Affected versions begin at 5.0.0.