Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-34179

32
FAUCET Score

CVE-2026-34179 is a critical privilege escalation vulnerability affecting Canonical LXD versions 4.12 through 6.7, wherein the doCertificateUpdate function fails to properly validate the Type field during PUT/PATCH requests to certificate endpoints, enabling authenticated attackers with restricted TLS certificate access to escalate privileges to cluster administrator level. This vulnerability has a CVSS severity rating of 9.1 (CRITICAL) with a network-based attack vector requiring high privileges but no user interaction, resulting in complete compromise of confidentiality, integrity, and availability across connected systems. The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog, has low EPSS probability of exploitation at 0.0011, and shows inactive status on vulnerability tracking hotlists, suggesting no active exploitation in the wild at this time. However, the extreme CVSS score and the fundamental nature of the flaw (missing input validation in privileged operations) warrant immediate patching regardless of exploitation status. Organizations running affected LXD versions should prioritize updates to versions 6.8 or later to remediate this cluster-level privilege escalation risk.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.12.0, < 5.0.7CPE match
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
>= 5.1.0, < 5.21.5CPE match
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
>= 6.0.0, < 6.8.0CPE match
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
>= 4.12, <= 5.0.6CPE matchmatch criteria
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
>= 5.21.0, <= 5.21.4CPE matchmatch criteria
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.3
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.27%
Probability of exploitation in next 30 days
EPSS Percentile
19.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0027 is in the 2nd percentile among its peer group of 464 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

goGHSA-c3h3-89qf-jqm5critical

LXD: Update of type field in restricted TLS certificate allows privilege escalation to cluster admin

Apr 10, 2026

References

github.com / canonical/lxd/pull/17936
Issue TrackingPatch
github.com / canonical/lxd/security/advisories/GHSA-c3h3-89qf-jqm5
ExploitThird Party Advisory