Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-34177

32
FAUCET Score

CVE-2026-34177 is a privilege escalation vulnerability in Canonical LXD versions 4.12 through 6.7 that stems from an incomplete security denylist in the virtual machine option validation function. The flaw allows attackers to bypass restrictions on low-level VM configuration by injecting AppArmor rules and QEMU configurations that were not properly blocked, creating a bridge to the LXD Unix socket and enabling full cluster administrator compromise. The vulnerability carries a CVSS score of 9.1 (Critical) with a network-accessible attack vector and low complexity. It requires high privileges (can_edit permission on a VM instance), but once exploited results in complete compromise of confidentiality, integrity, and availability across connected systems. The attack can escalate from a restricted project VM to LXD cluster administrator access and ultimately to host root privileges. There is currently no evidence of active exploitation in the wild. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog, and the EPSS score of 0.0014 indicates minimal probability of exploitation within the next 30 days relative to other CVEs. Community attention appears limited at this time, though the critical severity and privilege escalation potential warrant prompt patching of affected LXD installations.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.12.0, < 5.0.7CPE match
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
>= 5.1.0, < 5.21.5CPE match
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
>= 6.0.0, < 6.8.0CPE match
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
>= 4.12, <= 5.0.6CPE matchmatch criteria
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
>= 5.21.0, <= 5.21.4CPE matchmatch criteria
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.3
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.36%
Probability of exploitation in next 30 days
EPSS Percentile
28.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0036 is in the 10th percentile among its peer group of 464 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

goGHSA-fm2x-c5qw-4h6fcritical

LXD: VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf

Apr 10, 2026

References

github.com / canonical/lxd/pull/17909
Issue Tracking
github.com / canonical/lxd/security/advisories/GHSA-fm2x-c5qw-4h6f
Third Party Advisory