CVE-2026-63296
PoC nicheAuthorization bypass in Canonical LXD instance migration
CVE-2026-63296 is an authorization bypass (CWE-863) in Canonical's LXD container and virtual machine manager in which configuration overrides supplied during an instance migration are not validated against the target project's enforced restrictions. An authenticated user permitted to move an instance into a different project can supply overrides that carry in configurations the target project would normally forbid, including high-privilege settings. Successful exploitation lets the attacker move instances with disallowed high-privilege configurations into restricted projects, bypassing project-level security controls; the 9.9 CVSS score reflects network exploitability, low privileges, no user interaction, and changed scope across confidentiality, integrity, and availability. Only LXD deployments that use multiple projects with enforced restrictions and grant migration rights to less-trusted authenticated users are meaningfully exposed. There is no evidence of in-the-wild exploitation: the flaw is not in CISA KEV, EPSS is 0.2% (16th percentile), and the only public reference is Canonical's GitHub security advisory (GHSA-gcr9-5q6r-w625).
What to do: Upgrade LXD to a patched release per Canonical's advisory GHSA-gcr9-5q6r-w625 and restart the LXD daemon; do not rely on version assumptions, verify the fixed version in the advisory for your install channel. Until patched, restrict instance-migration rights to trusted administrators and, if you use restricted projects, audit instances recently moved into them for disallowed high-privilege configuration and tighten which users can set instance configuration. The single public advisory reference and low EPSS (0.2%) indicate limited current attacker interest, but the critical CVSS warrants prompt patching in multi-tenant environments.
| Canonical LXD | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. An attacker can exploit this flaw to move instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.
- Vendors
- canonical
- Products
- lxd
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.