THREAT OPS › Threat News › [NVD] CVE-2026-16033 (HIGH 8.5) — A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the instance templates directory (sp
[NVD] CVE-2026-16033 (HIGH 8.5) — A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the instance templates directory (sp
CVE-2026-16033 CVSS: 8.5 HIGH Published: 2026-08-12T21:17:35.880
A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the instance templates directory (specifically affecting virtual machine / QEMU driver exe
Indicators of compromise
- CVE-2026-16033cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-16033