Sceawere

Vulnerability Detail

CVE-2026-87798UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

LXD CLI Arbitrary File Write

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.8
Creation Date
3h ago
Vendor
Canonical
Product
LXD
Attack Type
CWE-59 Improper link resolution before file access ('link following')
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine to write attacker-controlled files or directory trees to arbitrary paths on the client host, with the operator's privileges. The attacker does this by using a modified lxd-agent that returns inconsistent SFTP directory listings and Lstat results.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.8",
  "pubDate": "2026-09-28T14:17:21.290Z",
  "pubdate": "2026-09-28T14:17:21.290Z",
  "executiveSummary": "An improper link resolution vulnerability exists within the recursive file pull feature of the LXD CLI client, affecting Canonical LXD versions 4.0.2 through 6.9. This flaw permits a malicious actor with root-level access inside a compromised virtual machine to escape the intended directory boundaries during file transfer operations.\nThe vulnerability occurs when the LXD client interacts with a maliciously crafted lxd-agent. By manipulating SFTP directory listings and Lstat results, an attacker can trick the client into writing arbitrary files or directory structures to the host file system. The impact is significant, as the write operation is executed with the privileges of the user running the LXD CLI tool on the host. This effectively grants an attacker the ability to overwrite critical system files or inject malicious binaries, potentially leading to full host compromise depending on the operator's permission level.",
  "technicalDetails": "The vulnerability resides in the recursive file pull mechanism of the LXD CLI client, which fails to adequately sanitize and validate file paths provided by the lxd-agent during SFTP-based file transfers. The core issue is an improper link resolution that occurs when the client blindly trusts metadata returned by the agent.\nThe attack flow requires the attacker to replace or modify the lxd-agent within the target virtual machine. Once compromised, the agent is configured to return inconsistent data for subsequent requests. When the host-side LXD CLI client initiates a recursive pull (e.g., 'lxc file pull --recursive'), it requests directory listings and file attributes from the agent.\nStep-by-step exploitation: 1. The attacker prepares a malicious agent capable of responding to SFTP requests with forged Lstat attributes and directory entries. 2. The client initiates a recursive pull operation. 3. The attacker's agent provides a manipulated directory listing that includes symlinks or paths pointing to locations outside the designated target directory. 4. Due to the lack of strict validation in the client's path resolution logic, the client attempts to resolve and create these files on the host file system. 5. The client performs these write operations using the security context of the user executing the 'lxc' command, effectively writing attacker-controlled content to arbitrary paths on the host.\nThis vulnerability exploits the implicit trust relationship between the LXD client and the agent. By supplying malicious responses, the attacker bypasses path traversal protections that would normally prevent writing outside of the expected transfer directory. The exploitation is highly effective because it relies on the client's automated handling of directory structures, where a single maliciously crafted symlink can be used to redirect the file write operation to sensitive host paths (e.g., /home/user/.ssh/authorized_keys or system configuration files).\nAffected versions include LXD 4.0.2 up to 6.9. The vulnerability is mitigated in versions 4.0.14, 5.0.10, and 5.21.8. The attack requires no network exposure beyond the internal communication channel between the agent and the client, provided the attacker has already achieved root access within the guest VM."
}
CVE-2026-87798: LXD CLI Arbitrary File Write (MEDIUM Severity, CVSS: 5.8) | Sceawere