Aller au contenu principal
CRITICAL

CVE-2026-87799

CVSS v3

9.9

CRITICAL

Score EPSS

—

probabilité d’exploitation

CISA KEV

Non

exploitation connue

Exploitation

—

statut SSVC

Description

Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a project, or a malicious migration source server, to write attacker-controlled files to arbitrary paths on the target host as root, leading to full host compromise. The attacker does this with a crafted rsync or btrfs send stream that plants a symlink in the transfe

Détails techniques

Vecteur CVSS v3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Publiée le
2026-09-28
Dernière modification
2026-09-28

Questions fréquentes

Qu’est-ce que CVE-2026-87799 ?

Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a project, or a malicious migration source server, to write attacker-controlled files to arbitrary paths on the target host as root, leading to full host compromise. The attacker does this with a crafted rsync or btrfs send stream that plants a symlink in the transfe

CVE-2026-87799 est-elle activement exploitée ?

Aucune exploitation active de CVE-2026-87799 n’est confirmée.

Quel est le score CVSS de CVE-2026-87799 ?

CVE-2026-87799 a un score de base CVSS v3 de 9.9 (gravité CRITICAL), avec le vecteur CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.

CVE-2026-87799 touche-t-elle votre environnement ?

Utilisez isMalicious pour vérifier si l’une de vos IP ou l’un de vos domaines est associé aux IOC de cette vulnérabilité.

Sans carte bancaire · 500 vérifications gratuites par mois · Clé API gratuite