CVE-2026-34179: falha crítica em Canonical lxd
Update of type field in restricted TLS certificate allows privilege escalation to cluster admin
Publicada em
28Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 9.1epss 0.4%
probabilidade de exploração
0.4%top 66% das CVEs
exploração observada
nãonenhuma fonte reporta
In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests to /1.0/certificates/{fingerprint} for restricted TLS certificate users, allowing a remote authenticated attacker to escalate privileges to cluster admin.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Produtos afetados
Canonical · lxdCVEs relacionadas — Canonical lxd
No mesmo produto, das mais perigosas para as menos.
CVE-2026-28384CRITICALAuthenticated RCE via unsanitized compression_algorithmEPSS 0.9%CVE-2026-34178CRITICALImporting a crafted backup leads to project restriction bypassEPSS 0.7%CVE-2026-34177CRITICALVM lowlevel restriction bypass via raw.apparmor and raw.qemu.confEPSS 0.6%CVE-2026-12411HIGHBroken Access Control in Canonical LXD DevLXD APIEPSS 0.3%CVE-2026-28385MEDIUMSSRF via image import from URL allows internal network probing by authenticated usersEPSS 0.3%CVE-2026-3351LOWAuthorization Bypass in LXD GET /1.0/certificates EndpointEPSS 0.2%