An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. An attacker can exploit this flaw to move instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to LXD version 5.0.8 or later, or 5.12.6 or later, or 6.10 or later.
Workaround
No workaround given by the vendor.
References
History
Wed, 12 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical lxd |
|
| Vendors & Products |
Canonical
Canonical lxd |
Wed, 12 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. An attacker can exploit this flaw to move instances with disallowed high-privilege configurations into restricted projects, bypassing security controls. | |
| Title | Project restriction bypass via instance migration config override | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-08-12T19:27:45.736Z
Reserved: 2026-07-16T09:49:29.911Z
Link: CVE-2026-63296
No data.
Status : Received
Published: 2026-08-12T20:17:47.437
Modified: 2026-08-12T20:17:47.437
Link: CVE-2026-63296
No data.
OpenCVE Enrichment
Updated: 2026-08-12T23:00:05Z
Weaknesses