CVE-2026-63296
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.30%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. An attacker can exploit this flaw to move instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.
- CVSS 3.1
- 9.9 CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 0.30% probability · 23th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- canonical/lxd
- Source
- security@ubuntu.com
References
- https://github.com/canonical/lxd/security/advisories/GHSA-gcr9-5q6r-w625Vendor Advisory, Exploit, Mitigation
- https://github.com/canonical/lxd/security/advisories/GHSA-gcr9-5q6r-w625Vendor Advisory, Exploit, Mitigation
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.