Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-66898

Опубликовано: 12 авг. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 9.9

Описание

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside the designated restore directory.

РелизСтатусПримечание
devel

DNE

esm-apps/focal

needs-triage

esm-infra-legacy/xenial

needs-triage

esm-infra/bionic

needs-triage

jammy

DNE

noble

DNE

resolute

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 27%
0.00344
Низкий

9.9 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.9
nvd
20 дней назад

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside the designated restore directory.

CVSS3: 9.9
debian
20 дней назад

A path traversal vulnerability in LXD allows an attacker to manipulate ...

EPSS

Процентиль: 27%
0.00344
Низкий

9.9 Critical

CVSS3