Impact
An authorized user can exploit a flaw in the cluster migration operation to bypass the security restrictions of the target project. By issuing a POST request to /1.0/instances/{name} with migration:true, specifying a target project and a different cluster member, the destination node recognizes the request as an internal cluster notification and skips all project‑level restriction checks. This allows the attacker to deploy instance configurations that are otherwise disallowed within the restricted project, potentially compromising confidentiality, integrity, or availability of resources in that project.
Affected Systems
Canonical LXD installations that have not been updated to the patched versions described in the vendor release notes are affected. Vulnerable versions are those earlier than LXD 5.0.8, earlier than 5.21.6, or earlier than 6.10. Any earlier LXD release running in a cluster can be exploited.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.9, indicating critical severity. The EPSS score is unavailable, but the lack of listing in the CISA KEV catalog does not reduce the risk; the flaw is exploitable in environments where an attacker has authenticated privileges on a cluster node and the migration:endpoint exposed. An attacker requires no special conditions beyond legitimate access, making the risk high in any scenario where cross‑project migrations are enabled. Administrators should treat the vulnerability as critical and apply the patch as soon as possible.
OpenCVE Enrichment