CVE Database
/

CVE-2025-54286

Back to search

CVE-2025-54286

Published: Oct 2, 2025

Modified: Feb 26, 2026

PUBLISHED

Description

Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user consent via crafted HTML form submissions exploiting client certificate authentication.

VendorProductVersions

Canonical

LXD

affected
5.0 - < 5.0.5
affected
5.21 - < 5.21.4
affected
6.0 - < 6.5

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now