THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-16033 (HIGH 8.5) — A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the instance templates directory (sp

[NVD] CVE-2026-16033 (HIGH 8.5) — A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the instance templates directory (sp

lownvdPublished 2026-08-12

CVE-2026-16033 CVSS: 8.5 HIGH Published: 2026-08-12T21:17:35.880

A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the instance templates directory (specifically affecting virtual machine / QEMU driver exe

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-16033