CVE-2026-3351

Severity CVSS v4.0:
LOW
Type:
Unavailable / Other
Publication date:
03/03/2026
Last modified:
11/03/2026

Description

Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, restricted user to enumerate all certificate fingerprints trusted by the lxd server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:canonical:lxd:6.6:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*