CVE-2026-12411
Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite a
CVSS
8.4
Alto
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Publicado: 26 jun 2026 · Última mod.: 2 jul 2026 · CWE-639 · CWE-862
0.2%EPSS · 30 días0.3%
2026-08-092026-09-06
Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-864994.3 MED—
———In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission3hCVE-2026-864964.3 MED—
———In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses3hCVE-2026-864956.5 MED—
———In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects3hCVE-2026-864947.7 ALT—
———In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues3hCVE-2026-864896.5 MED—
———In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations3hCVE-2026-864886.5 MED—
———In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches3h