What happened
A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. The flaw is described as a path traversal vulnerability. A path-traversal weakness can allow crafted input to make an application reach files or directories outside the location it was supposed to access.
The reported flaw is best understood as an path-traversal weakness, rather than treating the CVE identifier or CVSS score as the whole story. The flaw is classified as an path traversal.
Reference sources
Reporting ends here. The sections below are CyberDeltaForce analysis and defender-focused interpretation.
What security teams should do now
- Inventory the affected product deployments and confirm whether the affected component and vulnerable release are present.
- Apply the vendor patch or mitigation for CVE-2026-66898 and validate the affected path after remediation.
What is not yet confirmed
- So far, researchers have not reported exploitation, but that can change as vendor, government or threat-intelligence reporting develops.