THREAT OPS › Threat News › [NVD] CVE-2026-63296 (CRITICAL 9.9) — An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the
[NVD] CVE-2026-63296 (CRITICAL 9.9) — An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the
CVE-2026-63296 CVSS: 9.9 CRITICAL Published: 2026-08-12T20:17:47.437
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. An attacke
Indicators of compromise
- CVE-2026-63296cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-63296