CVE-2026-63296

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. An attacker can exploit this flaw to move instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-12 20:17

Updated : 2026-09-11 15:15


NVD link : CVE-2026-63296

Mitre link : CVE-2026-63296

CVE.ORG link : CVE-2026-63296


JSON object : View

Products Affected

canonical

  • lxd
CWE
CWE-863

Incorrect Authorization