Junglewise Threat Intelligence

CVE-2026-66898: LXD path traversal in backup restore enables arbitrary file write

CVE-2026-66898 · Severity: critical · CVSS 9.9 · Published 2026-08-12

Technologies: Canonical LXD. Vendors: Canonical.

Executive brief

LXD is a container management system that allows users to create and manage lightweight Linux containers. A path traversal vulnerability in the backup import/restore feature allows an authenticated attacker to write arbitrary files as root outside the designated storage directory, enabling remote code execution on the host system. An attacker with container creation permissions can craft a malicious backup archive that exploits insufficient validation of instance names in backup metadata.

Technical details

The vulnerability is a path traversal (CWE-22) flaw in LXD's backup import handler. When processing an instance backup via POST /1.0/instances with application/octet-stream content, the backup.GetInfo() function reads the instance name directly from the backup/index.yaml metadata without validation. This unsanitized name flows directly into file system path construction via pool.CreateInstanceFromBackup() → vol.MountPath() → EnsureMountPath(os.Mkdir), bypassing the instance.ValidName() check which only applies to the JSON-dispatch code path. An authenticated user with can_create_instances project entitlement can exploit this by crafting a backup tarball with a malicious instance name containing path traversal sequences (e.g., "../../../../etc/cron.d/pwn"), causing LXD to create directories and unpack attacker-controlled content as root outside the storage pool. This yields arbitrary directory creation, arbitrary-content file write, and ultimately host remote code execution. Patches are available in versions 4.0.12, 5.0.4, 5.21.2, and 6.1.

Affected products

  • Canonical LXD < 4.0.12, 5.0.x < 5.0.4, 5.1.x - 5.20.x, 5.21.x < 5.21.2, 6.0.x, 7.0.x, 7.1.x, 7.2.x

Timeline

  • 2026-07-31: disclosed
  • 2026-08-12: patched

References

Related threats