Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-62420: LXD Cross-Project Migration Bypasses Security Restrictions
CVE-2026-62420 · published 22 days ago
Summary
An attacker with access to LXD can move instances into restricted projects without permission. This allows them to introduce unwanted configurations into those projects. To protect your systems, ensure that only authorized users can perform instance migrations and monitor your cluster for suspicious activity.
What to do
- Update canonical lxd to version 5.0.8 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | canonical | lxd | < 5.0.8 |
| Debian:12 | debian | lxd | All versions |
| Debian:13 | debian | lxd | All versions |
Original advisory text
Cross-project cluster migration bypasses project restrictions via cluster notification flag
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: <target>, and target: <member>, the destination node skips all project restriction checks because the request arrives as an internal cluster notification. An attacker can exploit this to introduce disallowed instance configurations into a restricted project.
References
- https://github.com/canonical/lxd/security/advisories/GHSA-v9wr-9r7q-fh4g vdb-entry vendor-advisory
- https://github.com/canonical/lxd/pull/18651 patch
- https://github.com/canonical/lxd/pull/18605 patch
- https://security-tracker.debian.org/tracker/CVE-2026-62420 Vendor Advisory
Severity
9.9
Critical
CVSS 3.1: 9.9 (MITRE)
CVSS 3.1: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-863Incorrect Authorization
Timeline
Published12 Aug 2026
Updated2 Sep 2026
First seen12 Aug 2026
Monitor software like this
Free during beta