Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5065 articles · 189145 vulns · 37/41 feeds (7d)
← Back to list
9.9
CVE-2026-63297PATCHED
Canonical · LXD

Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge

Description

An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a target project, LXD performs restriction checks before configuration merging is complete, creating a time-of-check to time-of-use (TOCTOU) condition. An attacker can exploit this flaw to copy instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.

Affected Products

VendorProductVersions
CanonicalLXD5.0.0, 5.21.0

References

  • https://github.com/canonical/lxd/security/advisories/GHSA-v989-qw7w-xvg4(vdb-entry, vendor-advisory)

Related News (1 articles)

Tier C
VulDB3h ago
CVE-2026-63297 | Canonical LXD up to 5.0.7/5.21.5 toctou
→ No new info (linked only)
CVSS 3.19.9 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
5.0.85.21.6
CWECWE-367, CWE-863
PublishedAug 12, 2026
Last enriched3h ago
Trending Score30
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-62420
Cross-project cluster migration bypasses project restrictions via cluster notification flag
Trending: 35
HIGHCVE-2026-63299
Storage volume cross-project move and snapshot restore bypass project disk limits
Trending: 32
CRITICALCVE-2026-63293
Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root
Trending: 30
CRITICALCVE-2026-63294
Root RCE via image backup.yaml symlink
Trending: 30
CRITICALCVE-2026-66898
Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE
Trending: 30

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 12, 2026
Discovered by ZDM
Aug 12, 2026
Patch Available
Aug 12, 2026