Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-62420: LXD Cross-Project Migration Bypasses Security Restrictions

CVE-2026-62420 · published 22 days ago
Summary

An attacker with access to LXD can move instances into restricted projects without permission. This allows them to introduce unwanted configurations into those projects. To protect your systems, ensure that only authorized users can perform instance migrations and monitor your cluster for suspicious activity.

What to do
  • Update canonical lxd to version 5.0.8 or later.
Affected software
Ecosystem VendorProductAffected versions
– canonical lxd < 5.0.8
Debian:12 debian lxd All versions
Debian:13 debian lxd All versions
Original advisory text
Cross-project cluster migration bypasses project restrictions via cluster notification flag
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: <target>, and target: <member>, the destination node skips all project restriction checks because the request arrives as an internal cluster notification. An attacker can exploit this to introduce disallowed instance configurations into a restricted project.
Severity
9.9 Critical
CVSS 3.1: 9.9 (MITRE)
CVSS 3.1: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-863Incorrect Authorization
Timeline
Published12 Aug 2026
Updated2 Sep 2026
First seen12 Aug 2026
Sources
CVE-2026-62420 · MITRE
Monitor software like this
Free during beta