Description
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. An attacker can exploit this flaw to move instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.
Published: 2026-08-12
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated LXD user can bypass project restrictions during instance migration because LXD does not validate the new configuration against the target project's enforced rules. The attacker may inject high‑privilege settings into the moved instance, effectively redefining project boundaries and compromising isolation controls. This flaw is a classic example of a configuration validation error (CWE‑863).

Affected Systems

Canonical LXD is affected. Versions prior to any of the following releases are vulnerable: 5.0.8, 5.12.6, or 6.10 (or later). Clients using these older versions should upgrade to one of the listed releases to eliminate the susceptibility. No additional vendor or product information is listed.

Risk and Exploitability

The CVSS score of 9.9 reflects the severity of this authorization bypass. EPSS is not published, so the probability of exploitation is unknown, but the lack of presence in CISA's KEV list does not mitigate the risk for environments already using LXD. The likely attack vector requires the attacker to be an authenticated user with migration privileges. Once access is achieved, the vulnerability enables the attacker to directly reconfigure instance settings during migration, thereby subverting project restrictions without needing network or privilege escalation beyond normal authentication.

Generated by OpenCVE AI on August 12, 2026 at 22:53 UTC.

Remediation

Vendor Solution

Upgrade to LXD version 5.0.8 or later, or 5.12.6 or later, or 6.10 or later.


OpenCVE Recommended Actions

  • Upgrade LXD to 5.0.8 or later, or 5.12.6 or later, or 6.10 or later to apply the vendor’s fix.
  • If an immediate upgrade is not possible, restrict the use of the migration feature to the highest‑trust users or temporarily disable instance migration for non‑administrative roles.
  • Monitor migration logs and enforce project restrictions manually until the official fix is applied to ensure that configuration overrides do not violate project policies.

Generated by OpenCVE AI on August 12, 2026 at 22:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Canonical
Canonical lxd
Vendors & Products Canonical
Canonical lxd

Wed, 12 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. An attacker can exploit this flaw to move instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.
Title Project restriction bypass via instance migration config override
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published:

Updated: 2026-08-13T14:25:39.478Z

Reserved: 2026-07-16T09:49:29.911Z

Link: CVE-2026-63296

cve-icon Vulnrichment

Updated: 2026-08-13T14:25:36.620Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-12T20:17:47.437

Modified: 2026-08-28T15:24:38.600

Link: CVE-2026-63296

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T23:00:05Z

Weaknesses