NONE · 0

CVE-2026-10720

Canonical MicroCeph versions from the squid and tentacle track are vulnerable to a path traversal issue in the remote-import API. Holders of a trusted cluster mTLS certificate (such as enrolled cluste...

Vulnerability Description

Canonical MicroCeph versions from the squid and tentacle track are vulnerable to a path traversal issue in the remote-import API. Holders of a trusted cluster mTLS certificate (such as enrolled cluster members) or join token can manipulate files in an imported remote cluster within the /var/snap/microceph confinement. This would allow daemon disruption and pollution of the cluster state.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-10720?

CVE-2026-10720 is a documented vulnerability. Canonical MicroCeph versions from the squid and tentacle track are vulnerable to a path traversal issue in the remote-import API. Holders of a trusted cluster mTLS certificate (such as enrolled cluste...

How severe is CVE-2026-10720?

CVSS scoring is not yet available for CVE-2026-10720. Check NVD for updates.

Is there a patch for CVE-2026-10720?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.