Junglewise Threat Intelligence

CVE-2026-10720: Canonical MicroCeph path traversal in remote-import API

CVE-2026-10720 · Severity: medium · CVSS 4 · Published 2026-06-19

Vendors: Canonical, Go.

Executive brief

Canonical MicroCeph, a tool for deploying scalable storage clusters, contains a security flaw in its remote-import feature. An authorized user or a compromised cluster member with valid credentials can manipulate files on other systems within the cluster. This could lead to service disruptions or the corruption of the storage cluster's internal state.

Technical details

A path traversal vulnerability (CWE-23) exists in the remote-import API of Canonical MicroCeph. The flaw resides in insufficient validation of remote paths during import operations. An attacker possessing a trusted cluster mTLS certificate or a valid join token can exploit this to manipulate files within the /var/snap/microceph confinement on a remote cluster node. This can result in daemon disruption and pollution of the cluster state. The issue is fixed in versions 19.2.3+snapcf306793a4 and 20.2.0+snapbe4e67380e.

Affected products

  • Canonical MicroCeph squid and tentacle tracks; 19.2.1+snap74c0060321 before 19.2.3+snapcf306793a4; 20.0.0 before 20.2.0+snapbe4e67380e

Timeline

  • 2026-06-09: patched: Fix merged in GitHub pull request #758
  • 2026-06-19: disclosed: CVE published to NVD

References