PT-2026-31597 · Canonical+1 · Lxd+1

Miha Purg

·

Published

2026-04-09

·

Updated

2026-05-13

·

CVE-2026-34179

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Canonical LXD versions 4.12 through 6.7
Description Canonical LXD versions 4.12 through 6.7 contain a flaw in the doCertificateUpdate function within lxd/certificates.go. This function fails to validate the Type field when processing PUT or PATCH requests to the /1.0/certificates/{fingerprint} API endpoint for restricted TLS certificate users. This allows a remote authenticated attacker to potentially escalate privileges to cluster admin.
Recommendations Update LXD to a version later than 6.7.

Exploit

Fix

LPE

Weakness Enumeration

Related Identifiers

BDU:2026-07539
CVE-2026-34179
GHSA-C3H3-89QF-JQM5

Affected Products

Lxd
Red Os