CRITICAL🇵🇱 Wersja polska

CVE-2026-34179

CVSS 9.1v3.1pub. 2026-04-09upd. 2026-04-22

In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests to /1.0/certificates/{fingerprint} for restricted TLS certificate users, allowing a remote authenticated attacker to escalate privileges to cluster admin.

🤖 AI Analysis
How it works

The vulnerability affects the doCertificateUpdate function in the lxd/certificates.go file. When a restricted TLS certificate user sends a PUT or PATCH request to the /1.0/certificates/{fingerprint} endpoint, the LXD server does not validate the Type field in the request body. An attacker can modify this field to escalate their privilege level to cluster administrator role without required authorization.

Impact

An authenticated attacker with limited TLS certificate user privileges can obtain full cluster administrator permissions in LXD, giving them control over the entire container environment, including all cluster nodes and hosted resources.

Mitigation & patch

Canonical LXD must be updated to a version higher than 6.7, which introduces a fix for Type field validation. Details are available in the vendor references: https://github.com/canonical/lxd/pull/17936 and https://github.com/canonical/lxd/security/advisories/GHSA-c3h3-89qf-jqm5

Who is affected

Canonical LXD in versions 4.12 to 6.7 inclusive

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Canonical Lxd

    APP
    Canonical
    4.12 – 5.0.65.21.0 – 5.21.46.0 – 6.7
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
References

Related vulnerabilities

CVE-2026-34177CRITICAL9.1PL ✓same product

Canonical LXD — privilege escalation przez niekompletną listę blokad VM

CVE-2026-34178CRITICAL9.1PL ✓same product

Canonical LXD: pominięcie ograniczeń projektu przy imporcie backupu

CVE-2026-9640HIGH7.2PL ✓same product

LXD: privilege escalation przez przywracanie snapshotów z pominięciem polityk

CVE-2026-12411HIGH8.4PL ✓same product

Canonical LXD: nieuprawniony dostęp do woluminów innych gości przez /dev/lxd

CVE-2025-54289HIGH7.4same product

Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read p...