CVE-2026-12411
Canonical lxd
Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled.
- CVSS
- 9.6
- EPSS
- 0.24% 14.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.27