Description
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: <target>, and target: <member>, the destination node skips all project restriction checks because the request arrives as an internal cluster notification. An attacker can exploit this to introduce disallowed instance configurations into a restricted project.
Published: 2026-08-12
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authorized user can exploit a flaw in the cluster migration operation to bypass the security restrictions of the target project. By issuing a POST request to /1.0/instances/{name} with migration:true, specifying a target project and a different cluster member, the destination node recognizes the request as an internal cluster notification and skips all project‑level restriction checks. This allows the attacker to deploy instance configurations that are otherwise disallowed within the restricted project, potentially compromising confidentiality, integrity, or availability of resources in that project.

Affected Systems

Canonical LXD installations that have not been updated to the patched versions described in the vendor release notes are affected. Vulnerable versions are those earlier than LXD 5.0.8, earlier than 5.21.6, or earlier than 6.10. Any earlier LXD release running in a cluster can be exploited.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.9, indicating critical severity. The EPSS score is unavailable, but the lack of listing in the CISA KEV catalog does not reduce the risk; the flaw is exploitable in environments where an attacker has authenticated privileges on a cluster node and the migration:endpoint exposed. An attacker requires no special conditions beyond legitimate access, making the risk high in any scenario where cross‑project migrations are enabled. Administrators should treat the vulnerability as critical and apply the patch as soon as possible.

Generated by OpenCVE AI on August 12, 2026 at 23:17 UTC.

Remediation

Vendor Solution

Upgrade to LXD version 5.0.8 or later, 5.21.6 or later, or 6.10 or later.


OpenCVE Recommended Actions

  • Upgrade LXD to version 5.0.8 or later, 5.21.6 or later, or 6.10 or later.
  • Restrict the migration endpoint to trusted users only to prevent unauthorized cross‑project instance movement.
  • Review project ACLs and ensure that restricted projects do not grant migration privileges to users who should not perform cross‑project moves.

Generated by OpenCVE AI on August 12, 2026 at 23:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Canonical
Canonical lxd
Vendors & Products Canonical
Canonical lxd

Wed, 12 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: <target>, and target: <member>, the destination node skips all project restriction checks because the request arrives as an internal cluster notification. An attacker can exploit this to introduce disallowed instance configurations into a restricted project.
Title Cross-project cluster migration bypasses project restrictions via cluster notification flag
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published:

Updated: 2026-08-12T19:27:44.371Z

Reserved: 2026-07-14T08:57:47.667Z

Link: CVE-2026-62420

cve-icon Vulnrichment

Updated: 2026-08-12T19:27:36.844Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-12T20:17:46.897

Modified: 2026-08-28T15:24:38.600

Link: CVE-2026-62420

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T23:30:10Z

Weaknesses