Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 09 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 09 Apr 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests to /1.0/certificates/{fingerprint} for restricted TLS certificate users, allowing a remote authenticated attacker to escalate privileges to cluster admin. | |
| Title | Update of type field in restricted TLS certificate allows privilege escalation to cluster admin | |
| Weaknesses | CWE-915 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-04-09T11:54:18.487Z
Reserved: 2026-03-26T09:24:08.449Z
Link: CVE-2026-34179
Updated: 2026-04-09T11:54:09.651Z
Status : Received
Published: 2026-04-09T10:16:21.963
Modified: 2026-04-09T12:16:18.557
Link: CVE-2026-34179
No data.
OpenCVE Enrichment
No data.