CVE-2026-63300: Canonical Lxd

Critical severity, CVSS 9.9. EPSS: 0.5% chance of exploitation in the next 30 days.

An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security restrictions. When migrating an instance between projects, LXD fails to validate the instance's configuration against the target project's enforced restrictions (such as restricted.containers.lowlevel, restricted.devices.*, and restricted.networks.access). An attacker can exploit this by creating a disallowed or high-privilege instance in an unrestricted project and subsequently moving it into the restricted project.

Affected products

  • Canonical Lxd: from 5.0.0, before 5.0.8 (fixed in 5.0.8); from 5.1, before 5.21.6 (fixed in 5.21.6); from 6.0, before 6.10 (fixed in 6.10)

Published 2026-08-12. Last modified 2026-09-11.