CVE-2026-3351
EUVD-2026-928603.03.2026, 13:16
Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, restricted user to enumerate all certificate fingerprints trusted by the lxd server.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| canonical | lxd | 6.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration