VYPR
High severity7.2NVD Advisory· Published Jun 26, 2026· Updated Jul 2, 2026

CVE-2026-9640

CVE-2026-9640

Description

A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration.. An authenticated project operator in a restricted multi-tenant environment can bypass policy restrictions by importing a maliciously crafted instance backup containing restricted configuration keys within a snapshot. When the snapshot is restored, these restricted keys are applied to the live instance without policy validation. Starting the modified instance grants the operator unauthorized host root access.

Affected products

3
  • Canonical/Lxdinferred3 versions
    >=6.0,<6.9 || >=5.21.0,<5.21.5 || >=5.0.0,<5.0.7+ 2 more
    • (no CPE)range: >=6.0,<6.9 || >=5.21.0,<5.21.5 || >=5.0.0,<5.0.7
    • cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*range: >=4.12,<5.0.7
    • (no CPE)range: <6.9, <5.21.5, <5.0.7

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.