A AegiFlow
MEDIUMCVSS 5.1EPSS 0.2%

CVE-2026-10720

Canonical MicroCeph: path traversal issue in the remote-import AP

Published
2026-06-19
Modified
2026-07-21
EPSS percentile
11%
Aliases
GHSA-xg3j-c7q4-f9ph
Sources
github-advisory

Summary

Canonical MicroCeph versions from the squid and tentacle track are vulnerable to a path traversal issue in the remote-import API. Holders of a trusted cluster mTLS certificate (such as enrolled cluster members) or join token can manipulate files in an imported remote cluster within the /var/snap/microceph confinement. This would allow daemon disruption and pollution of the cluster state.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/canonical/microceph/microceph0.0.0-20260609072127-5c2760d8fb76

Remediation: Upgrade to 0.0.0-20260609072127-5c2760d8fb76 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.