{"id":"CVE-2026-66898","summary":"Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE","details":"A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside the designated restore directory.","aliases":["GHSA-m857-c7gc-c984"],"modified":"2026-09-13T03:46:09.614395900Z","published":"2026-08-12T20:07:32.889Z","related":["openSUSE-SU-2026:21788-1"],"database_specific":{"cwe_ids":["CWE-22"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66898.json","cna_assigner":"canonical"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66898.json"},{"type":"ADVISORY","url":"https://github.com/canonical/lxd/security/advisories/GHSA-m857-c7gc-c984"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66898"},{"type":"PACKAGE","url":"https://github.com/canonical/lxd"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/canonical/lxd","events":[{"introduced":"03aab09f5b5cbdada00c6539877dcf5932fcde98"},{"fixed":"a55c9d0228552323d96cc330fb36f9471581c4ab"},{"introduced":"1e1349e3cbf30c1b2ce74e531d4dd0fd52c45be1"},{"fixed":"2101d7f6efdaa7762e6593c857cb524bfcd2859b"},{"introduced":"be2e2d38c65555880689da833c93d1e9d55ae94d"},{"fixed":"7d4a9933f4618cfe6ec8d18e2e8f91816e5ddbba"}],"database_specific":{"cpe":"cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.0.0"},{"fixed":"4.0.12"},{"introduced":"5.0.0"},{"fixed":"5.0.4"},{"introduced":"5.1"},{"fixed":"5.21.2"}],"source":"CPE_RANGE"}}],"versions":["show","lxd-4.0.11","lxd-4.0.9","lxd-5.17","lxd-5.16","lxd-5.15","lxd-5.14","lxd-5.13","lxd-5.12","lxd-5.11","lxd-5.0.2","lxd-5.10","lxd-5.9","lxd-5.8","lxd-5.7","lxd-5.6","lxd-5.5","lxd-5.0.1","lxd-5.4","lxd-5.3","lxd-5.2","lxd-5.1","lxd-5.0.0","lxd-4.0.8","lxd-4.0.7","lxd-4.0.6","lxd-4.0.5","lxd-4.0.4","lxd-4.0.3","lxd-4.0.2","lxd-4.0.1","lxd-4.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66898.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"}]}