Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5071 articles · 189145 vulns · 37/41 feeds (7d)
← Back to list
9.9
CVE-2026-63296PATCHED
Canonical · LXD

Project restriction bypass via instance migration config override

Description

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. An attacker can exploit this flaw to move instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.

Affected Products

VendorProductVersions
CanonicalLXD5.0.0, 5.21.0, 6.0

References

  • https://github.com/canonical/lxd/security/advisories/GHSA-gcr9-5q6r-w625(vdb-entry, vendor-advisory)

Related News (1 articles)

Tier C
VulDB3h ago
CVE-2026-63296 | Canonical LXD up to 5.0.7/5.21.5/6.9 Instance Migration authorization
→ No new info (linked only)
CVSS 3.19.9 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
5.0.85.21.66.10
CWECWE-863
PublishedAug 12, 2026
Last enriched2h ago
Trending Score30
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-62420
Cross-project cluster migration bypasses project restrictions via cluster notification flag
Trending: 35
HIGHCVE-2026-63299
Storage volume cross-project move and snapshot restore bypass project disk limits
Trending: 32
CRITICALCVE-2026-63293
Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root
Trending: 30
CRITICALCVE-2026-63294
Root RCE via image backup.yaml symlink
Trending: 30
CRITICALCVE-2026-66898
Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE
Trending: 30

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 12, 2026
Discovered by ZDM
Aug 12, 2026
Patch Available
Aug 12, 2026