PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-63296 Canonical CVE debrief

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. This flaw can be exploited to move instances with disallowed high-privilege configurations into restricted projects, bypassing security controls. The vulnerability has a critical CVSS score of 9.9, indicating a high severity. LXD administrators, users with instance migration privileges, security teams, and operators managing LXD instances should be aware of this vulnerability and review configurations to prevent exploitation. Evidence from official CVE Program record and NIST NVD detail page supports the existence of the vulnerability, but detailed information about affected products and versions is limited.

Vendor
Canonical
Product
LXD
CVSS
CRITICAL 9.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-12
Original CVE updated
2026-08-28
Advisory published
2026-08-12
Advisory updated
2026-08-28

Who should care

LXD administrators, users with instance migration privileges, security teams responsible for monitoring and enforcing project restrictions, and operators managing LXD instances should be aware of this vulnerability. They should review configurations, implement additional monitoring, and restrict configuration overrides to prevent exploitation. Vulnerability management teams should prioritize patching and verify configurations against target project restrictions. Security teams should also review compensating controls for exposed systems.

Technical summary

The vulnerability allows an authenticated attacker to bypass target project restrictions during instance migration in LXD. This is due to LXD accepting configuration overrides without validating them against the target project's enforced restrictions. The issue arises when migrating an instance to a target project, where LXD does not verify the new configuration against the target project's restrictions. This flaw can be exploited to move instances with disallowed high-privilege configurations into restricted projects, bypassing security controls. To address this, defenders should focus on validating configurations and restricting overrides.

Defensive priority

High priority due to critical CVSS score of 9.9 and potential for security control bypass.

Recommended defensive actions

  • Review and update LXD configurations to ensure alignment with target project restrictions.
  • Implement additional monitoring and validation for instance migrations.
  • Restrict configuration overrides during instance migration to authorized users.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

Evidence from official CVE Program record and NIST NVD detail page supports the existence of the vulnerability. However, detailed information about affected products and versions is limited. To verify, defenders should review official advisories and assess configurations against target project restrictions. Additional evidence from Ubuntu security tracker and public bug reports indicates potential impact on LXD instances. Further verification is needed to determine full scope.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-63296 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-63296

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-63296 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-63296

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.