Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to LXD version 5.0.8 or later, 5.21.6 or later, or 6.10 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 12 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical lxd |
|
| Vendors & Products |
Canonical
Canonical lxd |
Wed, 12 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: <target>, and target: <member>, the destination node skips all project restriction checks because the request arrives as an internal cluster notification. An attacker can exploit this to introduce disallowed instance configurations into a restricted project. | |
| Title | Cross-project cluster migration bypasses project restrictions via cluster notification flag | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-08-12T19:27:44.371Z
Reserved: 2026-07-14T08:57:47.667Z
Link: CVE-2026-62420
Updated: 2026-08-12T19:27:36.844Z
Status : Received
Published: 2026-08-12T20:17:46.897
Modified: 2026-08-12T20:17:46.897
Link: CVE-2026-62420
No data.
OpenCVE Enrichment
Updated: 2026-08-12T21:00:03Z