Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to LXD version 5.0.8 or later, 5.21.6 or later, or 6.10 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 12 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical lxd |
|
| Vendors & Products |
Canonical
Canonical lxd |
Wed, 12 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security restrictions. When migrating an instance between projects, LXD fails to validate the instance's configuration against the target project's enforced restrictions (such as restricted.containers.lowlevel, restricted.devices.*, and restricted.networks.access). An attacker can exploit this by creating a disallowed or high-privilege instance in an unrestricted project and subsequently moving it into the restricted project. | |
| Title | Cross-project instance move bypasses all project restrictions allowing host command execution | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-08-12T19:09:04.445Z
Reserved: 2026-07-16T10:01:05.653Z
Link: CVE-2026-63300
No data.
Status : Received
Published: 2026-08-12T20:17:47.953
Modified: 2026-08-12T20:17:47.953
Link: CVE-2026-63300
No data.
OpenCVE Enrichment
Updated: 2026-08-12T23:00:05Z