CVE-2026-85185
9.6 CRITICALpublic exploit availablePublished 2026-09-28 · Updated 2026-09-28
AI risk analysis
- Summary
- This flaw allows an authenticated client to traverse paths and delete arbitrary files or inject content on the host, leading to potential full host compromise.
- Exploitability
- Exploitation requires authentication and permission to create instances in a project. The attacker must send a crafted subvolume path containing ../ sequences.
- Blast radius
- If exploited, the attacker can gain full control over the host system, leading to severe data loss or system compromise.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to LXD 4.0.14, 5.0.10, 5.21.8, or 6.10 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is btrfs, the client can also place attacker-controlled content at arbitrary host paths, leading to full host compromise. The client does this with a crafted subvolume path containing ../ sequences, sent in either of two ways: in the optimized_header.yaml of an optimized btrfs backup, or in the btrfs migration header sent by a malicious migration source.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Weaknesses
CWE-22
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-71215PoC
- HIGHCVE-2026-81547
- CRITICALCVE-2026-100716PoC
- HIGHCVE-2025-1281
- HIGHCVE-2026-100520PoC
- HIGHCVE-2026-100682PoC
- CRITICALCVE-2026-101894PoC
- HIGHCVE-2026-12609PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.