Vulnerability Description
Canonical MicroCeph versions from the squid and tentacle track are vulnerable to a path traversal issue in the remote-import API. Holders of a trusted cluster mTLS certificate (such as enrolled cluster members) or join token can manipulate files in an imported remote cluster within the /var/snap/microceph confinement. This would allow daemon disruption and pollution of the cluster state.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-10720?
CVE-2026-10720 is a documented vulnerability. Canonical MicroCeph versions from the squid and tentacle track are vulnerable to a path traversal issue in the remote-import API. Holders of a trusted cluster mTLS certificate (such as enrolled cluste...
How severe is CVE-2026-10720?
CVSS scoring is not yet available for CVE-2026-10720. Check NVD for updates.
Is there a patch for CVE-2026-10720?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.