Vulnerability
Published 2026-09-15
Verified 2026-09-19

Canonical LXD: multiple critical flaws allow root command execution on host (WASOC 20260915003); CVSS 9.9

WA Cyber Security Unit advisory 20260915003 (15 September 2026, TLP:CLEAR) relays Canonical LXD updates for eight Critical issues (CVE-2026-66897, CVE-2026-66898, CVE-2026-63300, CVE-2026-63299, CVE-2026-63297, CVE-2026-63296, CVE-2026-63294, CVE-2026-62420), each listed at CVSS 9.9. Successful exploitation can let a remote attacker achieve root command execution on the LXD host. Affected lines per WASOC: LXD 6.x prior to 6.10; 5.21.x prior to 5.21.7; 5.0.x prior to 5.0.9; all versions prior to 4.0.13. Canonical GitHub advisory GHSA-q39m-8fx9-42fv (CVE-2026-66897 example) documents instance template path traversal to arbitrary host file write as root, with patched versions including 4.0.13, 5.0.9, 5.21.7, 6.9-ab8fad2, and 6.10; related LXD GHSAs cover further path-traversal / privilege issues in the same wave. WASOC reports no exploitation observed on Western Australian Government networks at time of writing. Patch to vendor-fixed LXD builds; review Canonical LXD security advisories for the full set. Primary: Canonical LXD GHSA index; AU wire: WASOC 20260915003.

Product
Canonical LXD
Versions
6.x prior to 6.10; 5.21.x prior to 5.21.7; 5.0.x prior to 5.0.9; all versions prior to 4.0.13 (WASOC). Example GHSA-q39m patched: 4.0.13, 5.0.9, 5.21.7, 6.9-ab8fad2, 6.10
CVSS
9.9
Exploited in Australia?
no
Patch to
Upgrade LXD to 6.10 / 5.21.7 / 5.0.9 / 4.0.13 (or newer vendor-fixed builds); apply all related Canonical LXD GHSAs in this wave

Primary: Canonical LXD GitHub Security Advisories (patched 4.0.13 / 5.0.9 / 5.21.7 / 6.10) · Vendor: Canonical LXD security advisories · CVE: CVE-2026-66897, CVE-2026-66898, CVE-2026-63300, CVE-2026-63299, CVE-2026-63297, CVE-2026-63296, CVE-2026-63294, CVE-2026-62420 · WASOC 20260915003 — Canonical LXD root command execution (15 Sep 2026)

vulnerabilities australia cloud