PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-62420 Canonical CVE debrief

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. The vulnerability occurs when moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: <target>, and target: <member>. The destination node skips all project restriction checks because the request arrives as an internal cluster notification. This could allow an attacker to introduce disallowed instance configurations into a restricted project. LXD users and administrators, particularly those with restricted projects, should review and apply vendor remediation to prevent potential security breaches. Affected operators, platform administrators, vulnerability management teams, and security teams should assess their exposure and implement compensating controls as needed. This may involve conducting inventory checks to identify potentially affected systems and monitoring for suspicious cross-project instance migration activity.

Vendor
Canonical
Product
LXD
CVSS
CRITICAL 9.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-12
Original CVE updated
2026-08-28
Advisory published
2026-08-12
Advisory updated
2026-08-28

Who should care

LXD users and administrators, particularly those with restricted projects, should review and apply vendor remediation to prevent potential security breaches. Affected operators, platform administrators, vulnerability management teams, and security teams should assess their exposure and implement compensating controls as needed. This may involve conducting inventory checks to identify potentially affected systems and monitoring for suspicious cross-project instance migration activity. Security teams should also review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance, and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Additionally, they should check relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. This vulnerability may impact organizations that use LXD for instance management, especially those with complex or multi-cluster environments. Therefore, it is crucial for these organizations to assess their exposure and take necessary actions to mitigate the vulnerability. This may involve implementing compensating controls, such as restricting instance configurations, monitoring for suspicious activity, and verifying the integrity of instance configurations. By taking these steps, organizations can help prevent potential security breaches and ensure the security of their LXD instances. To further mitigate the vulnerability, organizations should consider reviewing their current instance configurations, identifying potential weaknesses, and implementing additional security measures, such as multi-factor authentication and access controls. Furthermore, organizations should also consider conducting regular security audits and penetration testing to identify and address potential vulnerabilities before they can be exploited. By prioritizing the security of their LXD instances and taking proactive steps to mitigate the vulnerability, organizations can help protect their assets and prevent potential security breaches. The CVE record,

Technical summary

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. The vulnerability occurs when moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: <target>, and target: <member>. The destination node skips all project restriction checks because the request arrives as an internal cluster notification.

Defensive priority

Authenticated attackers may bypass security restrictions during cross-project instance migrations in LXD, potentially introducing disallowed configurations into restricted projects.

Recommended defensive actions

  • Review and apply vendor remediation for LXD
  • Implement compensating controls to monitor and restrict instance configurations
  • Conduct inventory checks to identify potentially affected systems
  • Monitor for suspicious cross-project instance migration activity
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE Program record and NVD vulnerability detail provide official metadata and vulnerability assessment. Additional source references are available from [email protected], including GitHub pull requests and security advisories. To verify affected scope, review compensating controls for exposed systems, and monitor for suspicious activity, defenders should check relevant logs and track exceptions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-62420 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-62420

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-62420 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-62420

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.