Canonical · Microceph · CVE-2026-10720
**Name of the Vulnerable Software and Affected Versions**
Canonical MicroCeph versions from the squid and tentacle track
**Description**
A path traversal issue exists in the remote-import API. Users possessing a join token or a trusted cluster mTLS certificate, such as enrolled cluster members, can manipulate files within an imported remote cluster inside the `/var/snap/microceph` confinement. This flaw can lead to daemon disruption and pollution of the cluster state.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.