Authorization Bypass in LXD Affects Canonical Products
CVE-2026-63296
9.9CRITICAL
What is CVE-2026-63296?
An authorization bypass flaw in LXD allows authenticated attackers to circumvent project restrictions during instance migration. When an instance is moved to a target project, LXD improperly accepts configuration overrides without validating them against the project's enforced restrictions. This vulnerability allows attackers to exploit the issue, enabling the migration of instances with high-privilege configurations into restricted projects while evading security controls.
Affected Version(s)
LXD Linux 5.0.0 < 5.0.8
LXD Linux 5.21.0 < 5.21.6
LXD Linux 6.0 < 6.10
