CVE-2026-34179
EUVD-2026-2087609.04.2026, 10:16
In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests to /1.0/certificates/{fingerprint} for restricted TLS certificate users, allowing a remote authenticated attacker to escalate privileges to cluster admin.EnginsightEarly Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| canonical | lxd | 4.12.0 ≤ 𝑥 < 5.0.7 | CNA |
| canonical | lxd | 5.1.0 ≤ 𝑥 < 5.21.5 | CNA |
| canonical | lxd | 6.0.0 ≤ 𝑥 < 6.8.0 | CNA |