The CVSS 9.9 rating for CVE-2026-63294 demands skepticism. A score that high paired with an EPSS of 0.01016 signals a fundamental disconnect: either the exploitation path is far more constrained than the severity implies, or something about the delivery mechanism is being glossed over. Given LXD's architecture, the latter is more likely.
LXD's archive import functionality processes backup.yaml without validating whether it's actually a file or a symlink. This is a textbook file-type assumption during I/O — the code reads