Authorization Bypass Vulnerability in LXD by Canonical
CVE-2026-62420

9.9CRITICAL

Key Information:

Vendor

Canonical

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-62420?

An authorization bypass vulnerability in LXD enables authenticated attackers to circumvent project security restrictions during cross-project instance migrations. When an instance is moved to a different cluster member with migration set to true, the destination node bypasses all project restriction checks, due to the request being treated as an internal cluster notification. This flaw allows attackers to introduce unauthorized instance configurations into restricted projects, posing a significant risk to organizational security and compliance.

Affected Version(s)

LXD Linux 5.0.0 < 5.0.8

LXD Linux 5.21.0 < 5.21.6

LXD Linux 6.0 < 6.10

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.