Vulnerability Platform
- AI
POCs
Reproduced
Malicious Packages
Security Intel
Resources
API Docs
Affected Products
Bounty Intel
Stats
About
Search
Upgrade
Settings
English
ไธญๆ
English
ๆฅๆฌ่ช
Theme
Default
Anime Pink
Feeling Rich
Login
Goal Reached
Thanks to every supporter โ we hit 100%!
Goal: 1000 CNY ยท Raised:
1359
CNY
100%
Buy Us a Coffee
Home
CVE-2026-34178
AI Analysis Summary
CVE-2026-34178
โ AI Deep Analysis Summary
Updated May 06, 2026
CVSS 9.1 ยท Critical
This is a
summary
of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis โ
Q1
What is this vulnerability? (Essence + Consequences)
๐จ **Essence**: LXD backup import validation flaw. ๐ **Consequences**: Authenticated attackers bypass project restrictions to gain **full host control**. ๐ฅ Critical integrity loss.
Q2
Root Cause? (CWE/Flaw)
๐ก๏ธ **CWE-20**: Improper Input Validation. ๐ **Flaw**: Only checks `backup/index.yaml`. โ Ignores `backup/container/backup.yaml` project limits. ๐ซ Missing scope checks.
Q3
Who is affected? (Versions/Components)
๐ข **Vendor**: Canonical. ๐ฆ **Product**: LXD. ๐ **Affected**: Versions **< 6.8**. ๐ณ Linux container management tool.
Q4
What can hackers do? (Privileges/Data)
๐ **Privileges**: Full Host Control. ๐ **Access**: Bypasses all project restrictions. ๐ **Data**: Complete compromise of the underlying host system. ๐ Unrestricted access.
Q5
Is exploitation threshold high? (Auth/Config)
๐ **Auth**: Requires **Authentication** (PR:H). ๐ **Network**: Remote (AV:N). โ๏ธ **Config**: Low complexity (AC:L). ๐ถ **UI**: None required. โ ๏ธ Moderate threshold due to auth need.
Q6
Is there a public Exp? (PoC/Wild Exploitation)
๐ซ **Public Exp**: No PoCs listed in data. ๐ต๏ธ **Wild Exp**: Unconfirmed. ๐ **Ref**: Vendor advisory & PR available. ๐ No immediate mass exploitation seen.
Q7
How to self-check? (Features/Scanning)
๐ **Check**: Scan for LXD versions < 6.8. ๐ **Audit**: Review backup import logs. ๐ ๏ธ **Tool**: Use CVE scanners for CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H. ๐ Verify `backup.yaml` handling.
Q8
Is it fixed officially? (Patch/Mitigation)
โ **Fixed**: Yes. ๐ฆ **Patch**: Update to **LXD 6.8+**. ๐ **Ref**: GitHub PR #17921. ๐ก๏ธ **Mitigation**: Create backup config from index properly.
Q9
What if no patch? (Workaround)
๐ง **Workaround**: Restrict backup import permissions. ๐ซ **Block**: Disable untrusted backup imports. ๐ **Isolate**: Limit user privileges. ๐ **Monitor**: Watch for suspicious import activities.
Q10
Is it urgent? (Priority Suggestion)
๐ฅ **Priority**: **CRITICAL**. ๐จ **Urgency**: High. ๐ **CVSS**: 9.8 (Critical). โก **Action**: Patch immediately. ๐ก๏ธ Protect host integrity.
Continue exploring
Vulnerability detail
Full AI analysis (login)
Canonical
CWE-20