Metrics
Affected Vendors & Products
No advisories yet.
Solution
Upgrade to LXD version 5.0.8 or later, 5.21.6 or later, or 6.10 or later.
Workaround
No workaround given by the vendor.
Wed, 12 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical lxd |
|
| Vendors & Products |
Canonical
Canonical lxd |
Wed, 12 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: <target>, and target: <member>, the destination node skips all project restriction checks because the request arrives as an internal cluster notification. An attacker can exploit this to introduce disallowed instance configurations into a restricted project. | |
| Title | Cross-project cluster migration bypasses project restrictions via cluster notification flag | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-08-12T19:27:44.371Z
Reserved: 2026-07-14T08:57:47.667Z
Link: CVE-2026-62420
Updated: 2026-08-12T19:27:36.844Z
Status : Received
Published: 2026-08-12T20:17:46.897
Modified: 2026-08-12T20:17:46.897
Link: CVE-2026-62420
No data.
OpenCVE Enrichment
Updated: 2026-08-12T23:30:10Z