An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints. This issue affected LXD from 4.12 through 6.6 and was fixed in the snap versions 5.0.6-e49d9f4 (channel 5.0/stable), 5.21.4-1374f39 (channel 5.21/stable), and 6.7-1f11451 (channel 6.0 stable). The channel 4.0/stable is not affected as it contains version 4.0.10.
Conclusion & alert: CVE-2026-28384 is rated Moderate Risk (54.7/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.25%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-22 | 0.15% | 0.25% | +0.10% |
| 2 | 2026-04-13 | 0.12% | 0.15% | +0.03% |
| 3 | 2026-03-13 | — | 0.12% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.4 | 4.0 | CRITICAL |
|
— | — | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2026-28384: 1 source package rows (incus); 2 state rows across 2 repos (3.23-community, edge-community); fixed 2, open 0. | https://security.alpinelinux.org/vuln/CVE-2026-28384 |
debian
|
not yet assigned | CVE-2026-28384 not yet assigned priority: Debian including 2 source packages (incus, lxd), 5 status rows across 4 suites (bookworm, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2026-28384 |
ubuntu
|
medium | CVE-2026-28384 medium priority: Ubuntu including 1 source packages (lxd), 7 status rows across 7 suites (bionic, focal, jammy, noble, questing, upstream, xenial): DNE 3, not-affected 3, released 1. | https://ubuntu.com/security/CVE-2026-28384 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||