CVE-2026-63299: Canonical Lxd

Critical severity, CVSS 9.9. EPSS: 0.6% chance of exploitation in the next 30 days.

An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations: the storagePoolVolumeTypePostMove function omits the limits.AllowVolumeCreation check before moving a volume across projects, and volume snapshot restore operations skip the AllowVolumeUpdate check when the configuration is nil (Config == nil). An attacker can exploit these flaws to allocate storage resources that exceed the administrative limits configured for a project.

Affected products

  • Canonical Lxd: from 5.0.0, before 5.0.8 (fixed in 5.0.8); from 5.1, before 5.21.6 (fixed in 5.21.6); from 6.0, before 6.10 (fixed in 6.10)

Published 2026-08-12. Last modified 2026-09-11.