{"id":"CVE-2026-9640","summary":"LXD Snapshot Import Privilege Escalation Vulnerability","details":"A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration.. An authenticated project operator in a restricted multi-tenant environment can bypass policy restrictions by importing a maliciously crafted instance backup containing restricted configuration keys within a snapshot. When the snapshot is restored, these restricted keys are applied to the live instance without policy validation. Starting the modified instance grants the operator unauthorized host root access.","aliases":["GHSA-ppq7-4492-5552"],"modified":"2026-08-12T03:51:47.794193857Z","published":"2026-06-26T15:50:38.453Z","database_specific":{"cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9640.json","cna_assigner":"canonical"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9640.json"},{"type":"ADVISORY","url":"https://github.com/canonical/lxd/security/advisories/GHSA-ppq7-4492-5552"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9640"},{"type":"FIX","url":"https://github.com/canonical/lxd/pull/18301"},{"type":"FIX","url":"https://github.com/canonical/lxd/pull/18303"},{"type":"FIX","url":"https://github.com/canonical/lxd/pull/18304"},{"type":"PACKAGE","url":"https://github.com/canonical/lxd"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/canonical/lxd","events":[{"introduced":"538ac3df036e4a8c0197d0f52d125be1b51879d0"},{"fixed":"7b1f0b6acefa288398ead8dda48b046d7b2795a3"},{"introduced":"761d134ceabd306f57acfb0ca51f59b03751a5b0"},{"fixed":"c5184be310b13a8be5d9a5f286bfa1c0c286716e"},{"introduced":"0"},{"fixed":"85f897013ccdb0f8f44d434a3b655d2edcefcfae"}],"database_specific":{"cpe":"cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.12"},{"fixed":"5.0.7"},{"introduced":"5.21.0"},{"fixed":"5.21.5"},{"introduced":"6.0"},{"fixed":"6.9"}],"source":"CPE_RANGE"}}],"versions":["lxd-6.8","lxd-5.17","lxd-5.16","lxd-5.15","lxd-5.14","lxd-5.13","lxd-5.12","lxd-5.11","lxd-5.0.2","lxd-5.10","lxd-5.9","lxd-5.8","lxd-5.7","lxd-5.6","lxd-5.5","lxd-5.0.1","lxd-5.4","lxd-5.3","lxd-5.2","lxd-5.1","lxd-5.0.0","lxd-4.24","lxd-4.23","lxd-4.22","lxd-4.21","lxd-4.20","lxd-4.19","lxd-4.18","lxd-4.17","lxd-4.16","lxd-4.15","lxd-4.14","lxd-4.13","lxd-4.12"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-9640.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}