CVE-2026-62420

EUVD-2026-57415
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: <target>, and target: <member>, the destination node skips all project restriction checks because the request arrives as an internal cluster notification. An attacker can exploit this to introduce disallowed instance configurations into a restricted project.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.9 CRITICAL
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 43.08%
Affected Products (NVD)
VendorProductVersion
canonicallxd
5.0.0 ≤
𝑥
< 5.0.8
canonicallxd
5.1 ≤
𝑥
< 5.21.6
canonicallxd
6.0 ≤
𝑥
< 6.10
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
lxd
bookworm
vulnerable
bookworm (security)
vulnerable
trixie
vulnerable
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
lxd
bionic
needs-triage
focal
needs-triage
jammy
dne
noble
dne
resolute
dne
xenial
needs-triage