CVE-2026-12411

Source
https://cve.org/CVERecord?id=CVE-2026-12411
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-12411.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-12411
Aliases
  • GHSA-hhf9-qw4v-72xp
Published
2026-06-26T15:27:55.111Z
Modified
2026-08-12T03:51:27.357729054Z
Severity
  • 8.4 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N CVSS Calculator
Summary
Broken Access Control in Canonical LXD DevLXD API
Details

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled.

Database specific
{
    "cwe_ids": [
        "CWE-639",
        "CWE-862"
    ],
    "cna_assigner": "canonical",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12411.json"
}
References

Affected packages

Git / github.com/canonical/lxd

Affected ranges

Type
GIT
Repo
https://github.com/canonical/lxd
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ],
    "extracted_events": [
        {
            "introduced": "6.6"
        },
        {
            "fixed": "6.9"
        }
    ],
    "cpe": "cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-12411.json"