An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. An attacker can exploit this flaw to move instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.
References
| Link | Resource |
|---|---|
| https://github.com/canonical/lxd/security/advisories/GHSA-gcr9-5q6r-w625 | Vendor Advisory Exploit Mitigation |
| https://github.com/canonical/lxd/security/advisories/GHSA-gcr9-5q6r-w625 | Vendor Advisory Exploit Mitigation |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-12 20:17
Updated : 2026-09-11 15:15
NVD link : CVE-2026-63296
Mitre link : CVE-2026-63296
CVE.ORG link : CVE-2026-63296
JSON object : View
Products Affected
canonical
- lxd
CWE
CWE-863
Incorrect Authorization
