Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-63296: LXD: Unauthorized Instance Migration into Restricted Projects

CVE-2026-63296 · published 22 days ago
Summary

An attacker can move instances into projects with restricted settings, bypassing security controls. This is a concern because it allows unauthorized access to sensitive data or systems. To mitigate this, ensure proper configuration and access controls are in place for LXD and its target projects.

What to do
  • Update canonical lxd to version 5.0.8 or later.
Affected software
Ecosystem VendorProductAffected versions
– canonical lxd < 5.0.8
Debian:12 debian lxd All versions
Debian:13 debian lxd All versions
Original advisory text
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD ac...
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. An attacker can exploit this flaw to move instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.
Severity
9.9 Critical
CVSS 3.1: 9.9 (MITRE)
CVSS 3.1: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-863Incorrect Authorization
Timeline
Published12 Aug 2026
Updated30 Aug 2026
First seen12 Aug 2026
Sources
CVE-2026-63296 · MITRE
Monitor software like this
Free during beta