CVE-2026-63295

EUVD-2026-57516
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as enforcing restricted.containers.privilege=isolated), LXD fails to enforce the requirement if an instance configuration omits the security.idmap.isolated key. An attacker can exploit this flaw by creating or updating an instance without explicitly setting security.idmap.isolated, bypassing the target project's security constraints.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 25.88%
Affected Products (NVD)
VendorProductVersion
canonicallxd
4.0.0 ≤
𝑥
< 4.0.12
canonicallxd
5.0.0 ≤
𝑥
< 5.0.8
canonicallxd
5.1 ≤
𝑥
< 5.21.6
canonicallxd
6.0 ≤
𝑥
< 6.10
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
lxd
bookworm
vulnerable
bookworm (security)
vulnerable
trixie
vulnerable
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
lxd
bionic
needs-triage
focal
needs-triage
jammy
dne
noble
dne
resolute
dne
xenial
needs-triage