{"id":"CVE-2026-86335","published":"2026-09-28T14:17:20.740","lastModified":"2026-09-28T17:17:51.407","description":"Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance import requests.","cvssScore":6.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N","cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://github.com/canonical/lxd/pull/18987","tags":[]},{"url":"https://github.com/canonical/lxd/pull/19001","tags":[]},{"url":"https://github.com/canonical/lxd/pull/19002","tags":[]},{"url":"https://github.com/canonical/lxd/pull/19003","tags":[]},{"url":"https://github.com/canonical/lxd/security/advisories/GHSA-j7p3-5g2v-69j8","tags":[]}],"exploitRefs":[{"url":"https://github.com/canonical/lxd/pull/18987","tags":[]},{"url":"https://github.com/canonical/lxd/pull/19001","tags":[]},{"url":"https://github.com/canonical/lxd/pull/19002","tags":[]},{"url":"https://github.com/canonical/lxd/pull/19003","tags":[]},{"url":"https://github.com/canonical/lxd/security/advisories/GHSA-j7p3-5g2v-69j8","tags":[]}],"hasPoc":true,"ai":null}