PT-2026-71224 · Canonical · Lxd
CVE-2026-62420
·
Published
2026-08-12
·
Updated
2026-09-02
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LXD (affected versions not specified)
Description
An authorization bypass allows an authenticated attacker to circumvent security restrictions of a target project during cross-project instance migrations. By using the 'POST /1.0/instances/{name}' endpoint with the parameters
migration, project, and target, the destination node fails to perform project restriction checks because the request is processed as an internal cluster notification. This allows an attacker to implement disallowed instance configurations within a restricted project.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lxd