PatchSiren cyber security CVE debrief
CVE-2026-28384 Canonical CVE debrief
Authenticated users can execute commands as the LXD daemon via API calls due to improper sanitization of the compression_algorithm parameter in Canonical LXD. This issue affects LXD versions from 4.12 through 6.6. The vulnerability allows for potential remote code execution and elevation of privileges to the LXD daemon level. LXD administrators should assess exposure and apply patches from snap versions 5.0.6-e49d9f4, 5.21.4-1374f39, or 6.7-1f11451. It is also recommended to review API call logs for suspicious activity and implement compensating controls to restrict access to LXD API endpoints.
- Vendor
- Canonical
- Product
- lxd
- CVSS
- CRITICAL 9.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-12
- Original CVE updated
- 2026-09-11
- Advisory published
- 2026-03-12
- Advisory updated
- 2026-09-11
Who should care
LXD administrators, DevOps teams, and security personnel responsible for LXD deployments should assess exposure and apply patches. They should also review API call logs for suspicious activity and implement compensating controls to restrict access to LXD API endpoints. Additionally, they should monitor for potential remote code execution and elevation of privileges, perform asset inventory to identify affected systems, and track exceptions and retest remdi
Why it matters
Authenticated users can execute commands as the LXD daemon via API calls due to improper sanitization of the compression_algorithm parameter in Canonical LXD. This issue affects LXD versions from 4.12 through 6.6, and patches are available in snap versions 5.0.6-e49d9f4, 5.21.4-1374f39, or 6.7-1f11451. LXD administrators should assess exposure and apply patches.
- Potential for authenticated remote code execution
- Elevation of privileges to LXD daemon level
- Possible disruption of LXD services
- Need for verification of affected versions and patch application
Technical summary
Improper sanitization of the compression_algorithm parameter in Canonical LXD allows authenticated, unprivileged users to execute commands as the LXD daemon via API calls to image and backup endpoints. This issue affects LXD versions from 4.12 through 6.6 and was fixed in snap versions 5.0.6-e49d9f4, 5.21.4-1374f39, or 6.7-1f11451. LXD administrators should assess exposure and apply patches to prevent potential remote code execution and elevation of privileges to the LXD daemon level. It is also recommended to review API call logs for suspicious activity and implement compensating controls to restrict access to LXD API endpoints.
Defensive priority
High priority for LXD administrators to assess exposure and apply patches
Recommended defensive actions
- Assess LXD deployment versions to identify potential exposure
- Apply patches from snap versions 5.0.6-e49d9f4, 5.21.4-1374f39, or 6.7-1f11451
- Review API call logs for suspicious activity
- Implement compensating controls to restrict access to LXD API endpoints
- Monitor for potential remote code execution and elevation of privileges
- Perform asset inventory to identify affected systems
- Track exceptions and retest remediated assets
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability, while issue tracking and patch references offer remediation paths. The vulnerability was fixed in snap versions 5.0.6-e49d9f4 (channel 5.0/stable), 5.21.4-1374f39 (channel 5.21/stable), and 6.7-1f11451 (channel 6.0 stable). The channel 4.0/stable is not affected as it contains version 4.0.10. LXD administrators should verify affected versions and apply patches.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-28384 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-28384
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-28384 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-28384
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://discourse.ubuntu.com/t/lxd-authenticated-remote-code-execution-fixes-available/78365
[email protected] - Issue Tracking
-
Source reference
Unverified legacy reference
URL: https://github.com/canonical/lxd/commit/043696a13171ace7dd4c2b32d34ce039ab629052
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/canonical/lxd/commit/7046979645c2ce1b63b2f9e60ddf6cbc4c4b78f9
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/canonical/lxd/commit/b7b411caf5c4971bfe2386c72128f44d7e2aaf4f
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/canonical/lxd/security/advisories/GHSA-4rmf-rcp8-2r9g
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.