CVE-2026-63296
Critical · CVSS 9.9- CVSS
- 9.9
- nvd
- EPSS
- 0.25%
- 16th pct
- KEV
- No
- Class
- oss containerizable
- CWE-863
Description
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. An attacker can exploit this flaw to move instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.
References
Status: profiled · ingested 2026-08-13T18:00:50.000Z