OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-97335

HIGH · CVSS 7.7 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability affects Canonical LXD versions 5.0.0 and later on Linux, allowing authenticated users with permissions to create custom storage volumes to access and read custom storage volumes from other projects on the server. This is achieved through a crafted request that bypasses proper authorization checks, potentially exposing sensitive data, including snapshots and configurations. Organizations utilizing LXD for container management should prioritize patching to versions 5.0.10, 5.21.8, or 6.10 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-97335
Severity
HIGH
CVSS
7.7
EPSS
0.21%
Linux

Original NVD Description

Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create custom volumes in a project to copy, and so read, any custom storage volume from any other project on the server, including its snapshots and configuration. The client does this with a crafted request that sets a source volume and source.project but omits source.type.