Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, restricted user to enumerate all certificate fingerprints trusted by the lxd server.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 03 Mar 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, restricted user to enumerate all certificate fingerprints trusted by the lxd server. | |
| Title | Authorization Bypass in LXD GET /1.0/certificates Endpoint | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-03-03T12:49:25.034Z
Reserved: 2026-02-27T16:38:38.974Z
Link: CVE-2026-3351
No data.
Status : Received
Published: 2026-03-03T13:16:21.350
Modified: 2026-03-03T13:16:21.350
Link: CVE-2026-3351
No data.
OpenCVE Enrichment
No data.
Weaknesses