CVE-2026-28384 is a critical vulnerability in Canonical LXD versions 4.12 through 6.6, stemming from improper sanitization of the compression_algorithm parameter. This flaw allows an authenticated, unprivileged user to execute commands as the LXD daemon on the server via API calls to image and backup endpoints. With a CVSS score of 9.4 (Critical), it presents a low-complexity network attack vector requiring only low privileges, leading to high impacts on confidentiality, integrity, and availability. While patches are available in specific snap versions (5.0.6, 5.21.4, 6.7), there is currently no evidence of active exploitation, public exploit code, or significant community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0.0, < 5.0.6CPE match | cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:* | ||
>= 5.21.0, < 5.21.4CPE match | cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:* | ||
>= 6.0, < 6.7CPE match | cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.