CVE-2026-3351

Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, restricted user to enumerate all certificate fingerprints trusted by the lxd server.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:canonical:lxd:6.6:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-03 13:16

Updated : 2026-03-11 18:41


NVD link : CVE-2026-3351

Mitre link : CVE-2026-3351

CVE.ORG link : CVE-2026-3351


JSON object : View

Products Affected

linux

  • linux_kernel

canonical

  • lxd
CWE
CWE-862

Missing Authorization