CVE-2026-3351

MEDIUM

Canonical LXD 6.6 - Auth Bypass

Title source: llm
STIX 2.1

Description

Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, restricted user to enumerate all certificate fingerprints trusted by the lxd server.

Scores

CVSS v3 4.3
EPSS 0.0002
EPSS Percentile 6.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
canonical/lxd 6.6
canonical/lxd 0 - 0.0.0-20260224152359-d936c90d47cfGo
Published Mar 03, 2026
Tracked Since Mar 03, 2026