Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-62420

CRITICAL NVD
CVSS Score 9.9
Severity CRITICAL
Published Aug 12, 2026
Vendor unknown

Description

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: <target>, and target: <member>, the destination node skips all project restriction checks because the request arrives as an internal cluster notification. An attacker can exploit this to introduce disallowed instance configurations into a restricted project.

References