Impact
An authenticated LXD user can bypass project restrictions during instance migration because LXD does not validate the new configuration against the target project's enforced rules. The attacker may inject high‑privilege settings into the moved instance, effectively redefining project boundaries and compromising isolation controls. This flaw is a classic example of a configuration validation error (CWE‑863).
Affected Systems
Canonical LXD is affected. Versions prior to any of the following releases are vulnerable: 5.0.8, 5.12.6, or 6.10 (or later). Clients using these older versions should upgrade to one of the listed releases to eliminate the susceptibility. No additional vendor or product information is listed.
Risk and Exploitability
The CVSS score of 9.9 reflects the severity of this authorization bypass. EPSS is not published, so the probability of exploitation is unknown, but the lack of presence in CISA's KEV list does not mitigate the risk for environments already using LXD. The likely attack vector requires the attacker to be an authenticated user with migration privileges. Once access is achieved, the vulnerability enables the attacker to directly reconfigure instance settings during migration, thereby subverting project restrictions without needing network or privilege escalation beyond normal authentication.
OpenCVE Enrichment