{"id":"CVE-2026-34179","aliases":["GHSA-c3h3-89qf-jqm5"],"url":"https://o3.security/vulnerability/CVE-2026-34179","summary":"Update of type field in restricted TLS certificate allows privilege escalation to cluster admin","details":"In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests to /1.0/certificates/{fingerprint} for restricted TLS certificate users, allowing a remote authenticated attacker to escalate privileges to cluster admin.","published":"2026-04-09T09:22:14.693Z","modified":"2026-08-07T11:31:07.944671109Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/canonical/lxd","fixedVersion":null}],"fix":{"url":"https://github.com/canonical/lxd/pull/17936","label":"canonical/lxd#17936"},"references":[{"type":"WEB","url":"https://github.com/canonical"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34179.json"},{"type":"ADVISORY","url":"https://github.com/canonical/lxd/security/advisories/GHSA-c3h3-89qf-jqm5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34179"},{"type":"FIX","url":"https://github.com/canonical/lxd/pull/17936"},{"type":"PACKAGE","url":"https://github.com/canonical/lxd"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:07.944671109Z"}}