Back

MEDIUM

Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated`

Published Aug 12, 2026

Description

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as enforcing restricted.containers.privilege=isolated), LXD fails to enforce the requirement if an instance configuration omits the security.idmap.isolated key. An attacker can exploit this flaw by creating or updating an instance without explicitly setting security.idmap.isolated, bypassing the target project's security constraints.

Affected products

Remediation

Vendor solution

Upgrade to LXD version 4.0.12 or later, 5.0.8 or later, or 5.12.6 or later, or 6.10 or later.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner canonical
Published Aug 12, 2026
Updated Aug 13, 2026
Reserved Jul 16, 2026
CISA Vulnrichment
Updated Aug 13, 2026
NVD
Status Analyzed
Modified Sep 11, 2026
Red Hat
Severity n/a
Public date n/a