Back

CRITICAL

Project restriction bypass via instance migration config override

Published Aug 12, 2026

Description

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. An attacker can exploit this flaw to move instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.

Affected products

Remediation

Vendor solution

Upgrade to LXD version 5.0.8 or later, or 5.12.6 or later, or 6.10 or later.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner canonical
Published Aug 12, 2026
Updated Aug 13, 2026
Reserved Jul 16, 2026
CISA Vulnrichment
Updated Aug 13, 2026
NVD
Status Analyzed
Modified Sep 11, 2026
Red Hat
Severity n/a
Public date n/a