Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-63297: LXD Security: Unauthorized Instance Copy in Restricted Projects

CVE-2026-63297 · published 22 days ago
Summary

An attacker with valid access can copy instances into projects with tighter security controls. This could allow them to gain more privileges or access sensitive data. To mitigate this risk, ensure all instance configurations are properly validated and restricted access is enforced.

What to do
  • Update canonical lxd to version 5.0.8 or later.
Affected software
Ecosystem VendorProductAffected versions
– canonical lxd < 5.0.8
Debian:12 debian lxd All versions
Debian:13 debian lxd All versions
Original advisory text
An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance c...
An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a target project, LXD performs restriction checks before configuration merging is complete, creating a time-of-check to time-of-use (TOCTOU) condition. An attacker can exploit this flaw to copy instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.
Severity
9.9 Critical
CVSS 3.1: 9.9 (MITRE)
CVSS 3.1: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-367Time-of-check Time-of-use (TOCTOU) Race Condition
CWE-863Incorrect Authorization
Timeline
Published12 Aug 2026
Updated24 Aug 2026
First seen12 Aug 2026
Sources
CVE-2026-63297 · MITRE
Monitor software like this
Free during beta