CVE-2026-34177 is a privilege escalation vulnerability in Canonical LXD versions 4.12 through 6.7 that stems from an incomplete security denylist in the virtual machine option validation function. The flaw allows attackers to bypass restrictions on low-level VM configuration by injecting AppArmor rules and QEMU configurations that were not properly blocked, creating a bridge to the LXD Unix socket and enabling full cluster administrator compromise. The vulnerability carries a CVSS score of 9.1 (Critical) with a network-accessible attack vector and low complexity. It requires high privileges (can_edit permission on a VM instance), but once exploited results in complete compromise of confidentiality, integrity, and availability across connected systems. The attack can escalate from a restricted project VM to LXD cluster administrator access and ultimately to host root privileges. There is currently no evidence of active exploitation in the wild. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog, and the EPSS score of 0.0014 indicates minimal probability of exploitation within the next 30 days relative to other CVEs. Community attention appears limited at this time, though the critical severity and privilege escalation potential warrant prompt patching of affected LXD installations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.12.0, < 5.0.7CPE match | cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:* | ||
>= 5.1.0, < 5.21.5CPE match | cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.8.0CPE match | cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:* | ||
>= 4.12, <= 5.0.6CPE matchmatch criteria | cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:* | ||
>= 5.21.0, <= 5.21.4CPE matchmatch criteria | cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.