CRITICAL 9.9 NVD

CVE-2026-63296

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. An attacker can exploit this flaw to move instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.

References

Published: 2026-08-12 · Source: NVD · Feed updated: 2026-08-12
This critical severity vulnerability with a CVSS score of 9.9 was published on 2026-08-12 via NVD.

Risk Timeline

CVE Disclosed2026-08-12 · -1 days ago

Remediation Resources

vulnfeed aggregates 10542 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.