Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-xg3j-c7q4-f9ph | Canonical MicroCeph: path traversal issue in the remote-import AP |
| Link | Providers |
|---|---|
| https://github.com/canonical/microceph/pull/758 |
|
Wed, 24 Jun 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical microceph |
|
| Vendors & Products |
Canonical
Canonical microceph |
Mon, 22 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 19 Jun 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Canonical MicroCeph versions from the squid and tentacle track are vulnerable to a path traversal issue in the remote-import API. Holders of a trusted cluster mTLS certificate (such as enrolled cluster members) or join token can manipulate files in an imported remote cluster within the /var/snap/microceph confinement. This would allow daemon disruption and pollution of the cluster state. | |
| Title | MicroCeph path traversal issue in the remote-import API | |
| Weaknesses | CWE-23 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-06-22T15:02:10.804Z
Reserved: 2026-06-02T22:29:08.534Z
Link: CVE-2026-10720
Updated: 2026-06-22T15:02:06.911Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-24T20:41:55Z
Github GHSA