Skip to content
ThreatCluster

Critical Privilege Escalation Vulnerabilities in Canonical LXD Discovered

First seen 13 Apr 2026, 09:43 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 14, 2026 at 09:29 UTC
  • •Three critical vulnerabilities in Canonical LXD allow privilege escalation to host root.
  • •CVE-2026-34177 enables attackers to inject malicious configurations via AppArmor and QEMU.
  • •Organizations must patch affected systems and enhance monitoring to prevent exploitation.

Three critical vulnerabilities (CVE-2026-34177, CVE-2026-34178, CVE-2026-34179) have been identified in Canonical LXD versions 4.12 through 6.7, allowing authenticated users to escalate privileges to cluster admin and host root. CVE-2026-34177 involves an incomplete denylist that lets attackers inject AppArmor rules and QEMU configurations, compromising the host. CVE-2026-34178 allows attackers to bypass project restrictions by manipulating configuration files during backup creation. CVE-2026-34179 enables a restricted TLS certificate user to gain admin privileges by altering their certificate type. The vulnerabilities impact availability, confidentiality, and integrity of systems using LXD. Organizations are urged to prioritize patching and enhance monitoring capabilities. The vulnerabilities were published on April 9, 2026, and pose a significant risk to affected systems. Immediate action is recommended to mitigate potential exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 177d ago How this analysis works

Timeline

2026-04-09
CVE-2026-34177, CVE-2026-34178, CVE-2026-34179 published
2026-04-13
Vulnerabilities reported by CCB and NVD

More articles in this cluster (3)

Following this threat?

Track CVE-2026-34177 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed