LXD hit by three critical flaws rated up to 9.9
Three LXD vulnerabilities were disclosed: CVE-2026-87799 (symlink traversal during migration) and CVE-2026-85526, CVE-2026-85185 (path traversal when restoring btrfs backups). All let an authenticated user write files as root on the host. Fixes ship in 4.0.14, 5.0.10, 5.21.8 and 6.10.
- CVE-2026-87799 and CVE-2026-85526 score 9.9 on CVSSv3, CVE-2026-85185 scores 9.6
- LXD 4.0+ is affected; btrfs flaws start at 4.0.2
- Fixed releases: 4.0.14, 5.0.10, 5.21.8 and 6.10
- ZoomEye matched 12,153 LXD assets as of September 29, 2026
Read next
Security