9.9
CVE-2026-63300
- EPSS 0.29%
- Veröffentlicht 12.08.2026 19:09:04
- Zuletzt bearbeitet 11.09.2026 15:21:14
- Erkennungen
Cross-project instance move bypasses all project restrictions allowing host command execution
An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security restrictions. When migrating an instance between projects, LXD fails to validate the instance's configuration against the target project's enforced restrictions (such as restricted.containers.lowlevel, restricted.devices.*, and restricted.networks.access). An attacker can exploit this by creating a disallowed or high-privilege instance in an unrestricted project and subsequently moving it into the restricted project.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.29% | 0.215 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Canonical | 9.9 | 3.1 | 6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
https://github.com/canonical/lxd/pull/18651
https://github.com/canonical/lxd/pull/18605
https://github.com/canonical/lxd/security/advisories/GHSA-5g5r-wh97-qcq2