CVE-2026-63300
Cross-project instance move bypasses all project restrictions allowing host command execution
An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security restrictions. When migrating an instance between projects, LXD fails to validate the instance's configuration against the target project's enforced restrictions (such as restricted.containers.lowlevel, restricted.devices.*, and restricted.networks.access). An attacker can exploit this by creating a disallowed or high-privilege instance in an unrestricted project and subsequently moving it into the restricted project.
| CWE | CWE-862 |
| Vendor | canonical |
| Product | lxd |
| Ecosystems | |
| Industries | Technology |
| Published | Aug 12, 2026 |
Get instant alerts for canonical lxd
Be the first to know when new critical vulnerabilities affecting canonical lxd are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H