PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-28384 Canonical CVE debrief

Authenticated users can execute commands as the LXD daemon via API calls due to improper sanitization of the compression_algorithm parameter in Canonical LXD. This issue affects LXD versions from 4.12 through 6.6. The vulnerability allows for potential remote code execution and elevation of privileges to the LXD daemon level. LXD administrators should assess exposure and apply patches from snap versions 5.0.6-e49d9f4, 5.21.4-1374f39, or 6.7-1f11451. It is also recommended to review API call logs for suspicious activity and implement compensating controls to restrict access to LXD API endpoints.

Vendor
Canonical
Product
lxd
CVSS
CRITICAL 9.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-12
Original CVE updated
2026-09-11
Advisory published
2026-03-12
Advisory updated
2026-09-11

Who should care

LXD administrators, DevOps teams, and security personnel responsible for LXD deployments should assess exposure and apply patches. They should also review API call logs for suspicious activity and implement compensating controls to restrict access to LXD API endpoints. Additionally, they should monitor for potential remote code execution and elevation of privileges, perform asset inventory to identify affected systems, and track exceptions and retest remdi

Why it matters

Authenticated users can execute commands as the LXD daemon via API calls due to improper sanitization of the compression_algorithm parameter in Canonical LXD. This issue affects LXD versions from 4.12 through 6.6, and patches are available in snap versions 5.0.6-e49d9f4, 5.21.4-1374f39, or 6.7-1f11451. LXD administrators should assess exposure and apply patches.

  • Potential for authenticated remote code execution
  • Elevation of privileges to LXD daemon level
  • Possible disruption of LXD services
  • Need for verification of affected versions and patch application

Technical summary

Improper sanitization of the compression_algorithm parameter in Canonical LXD allows authenticated, unprivileged users to execute commands as the LXD daemon via API calls to image and backup endpoints. This issue affects LXD versions from 4.12 through 6.6 and was fixed in snap versions 5.0.6-e49d9f4, 5.21.4-1374f39, or 6.7-1f11451. LXD administrators should assess exposure and apply patches to prevent potential remote code execution and elevation of privileges to the LXD daemon level. It is also recommended to review API call logs for suspicious activity and implement compensating controls to restrict access to LXD API endpoints.

Defensive priority

High priority for LXD administrators to assess exposure and apply patches

Recommended defensive actions

  • Assess LXD deployment versions to identify potential exposure
  • Apply patches from snap versions 5.0.6-e49d9f4, 5.21.4-1374f39, or 6.7-1f11451
  • Review API call logs for suspicious activity
  • Implement compensating controls to restrict access to LXD API endpoints
  • Monitor for potential remote code execution and elevation of privileges
  • Perform asset inventory to identify affected systems
  • Track exceptions and retest remediated assets

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, while issue tracking and patch references offer remediation paths. The vulnerability was fixed in snap versions 5.0.6-e49d9f4 (channel 5.0/stable), 5.21.4-1374f39 (channel 5.21/stable), and 6.7-1f11451 (channel 6.0 stable). The channel 4.0/stable is not affected as it contains version 4.0.10. LXD administrators should verify affected versions and apply patches.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-28384 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-28384

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-28384 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-28384

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.