Canonical LXD disclosed and patched multiple flaws that let authenticated users bypass project-level restrictions during cross-project moves, copies, clustered migrations, and restore operations. The most severe issues, tracked as CVE-2026-63300 and CVE-2026-62420, carry CVSS 9.9 ratings and allow attackers with instance-creation rights in a restricted project to introduce disallowed instance configurations by first creating them in an unrestricted project or by abusing clustered migration flows that were treated as internal notifications. The bypasses could defeat controls such as restricted.containers.lowlevel, restricted.devices.*, and restricted.networks.access, potentially enabling host command execution or other high-impact policy violations.
A related flaw, CVE-2026-63299, lets authenticated users evade project disk and volume limits during cross-project storage volume moves and snapshot restores, with a CVSS 8.5 score. Canonical addressed the issues in LXD pull requests #18605 and #18651, adding validation of target-project restrictions for instance moves and copies, enforcing snapshot restrictions during backup restore, and hardening checks in the stable 5.21 branch. Organizations using LXD, especially clustered deployments and restricted multi-tenant projects, should upgrade to the latest patched release and review project restriction and migration controls.

Get the actors, campaigns, and ATT&CK mapping behind it.
7 events from the most recent confirmed update back to the earliest known activity.
A CVE record was published for a high-severity LXD authorization bypass affecting cross-project volume moves and volume snapshot restores, allowing authenticated users to evade project-level disk and volume limits.
A CVE record was published for a critical LXD authorization bypass in clustered cross-project migrations where a destination node treats the request as an internal cluster notification and skips project restriction checks.
A CVE record was published for a critical LXD improper validation flaw in instancePostMigration that lets an authenticated attacker bypass restricted-project controls by moving an instance from an unrestricted project into a restricted one, potentially enabling host command execution.
Kadin Sayani force-pushed the stable-5.21 backport pull request #18651 and marked it ready for review, carrying the same hardening changes to enforce target-project restrictions during cross-project operations and backup restore.
Canonical opened and marked ready for review a security hardening pull request on the main branch that added target-project restriction checks for cross-project instance moves, copies, and backup restores as further hardening for GHSA-47w9-6r3f-938g.
Tomponline merged pull request #18651 into canonical:stable-5.21 with 34 checks passing. The backport included additional enforcement for cross-project instance moves, cross-project copies, and snapshot restrictions during backup restore.
Tomponline merged pull request #18605 into canonical:main, bringing in checks that enforce project restrictions during cross-project instance moves and copies and during backup restores involving snapshots. The merged PR also included tests to prevent bypass of restricted project policies.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
5 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.