Canonical LXD Privilege Escalation Vulnerability in TLS Certificate Management

Vulnerability

A vulnerability in Canonical LXD versions 4.12 through 6.7 allows remote authenticated attackers to escalate privileges to cluster admin. The issue arises in the 'doCertificateUpdate' function, which fails to properly validate the 'Type' field when processing PUT/PATCH requests to '/1.0/certificates/{fingerprint}' for users with restricted TLS certificates. This oversight enables attackers to manipulate certificate types, bypassing authorization controls and gaining elevated privileges.

Impact

Exploitation of this vulnerability allows restricted TLS certificate users to escalate privileges to cluster admin, with immediate effect and no logging of the permission change.

Reproduction

To reproduce this vulnerability, first create a restricted project and a restricted certificate as an admin. Then, as a restricted user, add a token for authentication and confirm access to the restricted project. Next, update the certificate type from 'client' to 'server' using a PUT/PATCH request. After the type change is confirmed, the project can be set to unrestricted, and a privileged container can be started, leading to root access on the host.

Remediation

Users can update to LXD versions 5.0.7, 5.21.5, 6.8, or 4.0.10.

Added: Apr 9, 2026, 10:48 AM
Updated: Apr 9, 2026, 10:48 AM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
5.0
exploitability
4.6
remediation
7.7
relevance
5.5
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.