CVE-2026-63296
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. An attacker can exploit this flaw to move instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63296.json, https://github.com/canonical/lxd/security/advisories/GHSA-gcr9-5q6r-w625, https://nvd.nist.gov/vuln/detail/CVE-2026-63296, https://github.com/canonical/lxd