Authorization Bypass Vulnerability in LXD by Canonical
CVE-2026-62420
9.9CRITICAL
What is CVE-2026-62420?
An authorization bypass vulnerability in LXD enables authenticated attackers to circumvent project security restrictions during cross-project instance migrations. When an instance is moved to a different cluster member with migration set to true, the destination node bypasses all project restriction checks, due to the request being treated as an internal cluster notification. This flaw allows attackers to introduce unauthorized instance configurations into restricted projects, posing a significant risk to organizational security and compliance.
Affected Version(s)
LXD Linux 5.0.0 < 5.0.8
LXD Linux 5.21.0 < 5.21.6
LXD Linux 6.0 < 6.10
