CVE-2026-86335
EUVD-2026-8825628.09.2026, 14:17
Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance import requests.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| canonical | lxd | 5.21.0 ≤ 𝑥 < 5.21.8 | CNA |
| canonical | lxd | 6.0 ≤ 𝑥 < 6.10 | CNA |
| canonical | lxd | 4.0 ≤ 𝑥 < 5.0.10 | CNA |
Debian Releases
Common Weakness Enumeration