#VU125586 Improper access control in LXD - CVE-2026-34178
Published: April 9, 2026
LXD
Linux Containers
Description
The vulnerability allows a remote user to bypass project restrictions and gain full host compromise.
The vulnerability exists due to improper access control in the LXD backup import process when importing a crafted instance backup archive. A remote privileged user can supply inconsistent backup/index.yaml and backup/container/backup.yaml files to bypass project restrictions and gain full host compromise.
Exploitation requires instance creation and operation permissions in a restricted project.