Skip to content
CVSS 9.9 · CRITICAL

CVE-2026-63294Root Command Execution on Host in LXD

A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml file when it exists as a symbolic link. An attacker can exploit this flaw by providing a malicious archive with a symlinked backup.yaml file, causing LXD to process unconfined configuration metadata and execute arbitrary commands with root privileges.

View on NVD

Analysis

A critical vulnerability in LXD allows an attacker to escape a container and execute commands as root on the host system. The flaw is triggered when importing a malicious image or backup archive containing a crafted symbolic link.

Relevant roles

LinuxCloudBackendCyberSecurityDocker

Severity

Score: 9.9(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: LOW
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-59

EPSS

No EPSS score yet (CVE may be too fresh).

Technical description

A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml file when it exists as a symbolic link. An attacker can exploit this flaw by providing a malicious archive with a symlinked backup.yaml file, causing LXD to process unconfined configuration metadata and execute arbitrary commands with root privileges.

Published: 8/12/2026, 8:17:47 PM
Last modified: 8/12/2026, 8:17:47 PM

References

HomeEventsBlogResourcesCoursesTeam