CVE-2026-63297Critical· 9.9▾ AbyssalPoC availableAn authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a tar…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 54.5 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
0.2% → 0.2%
An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a target project, LXD performs restriction checks before configuration merging is complete, creating a time-of-check to time-of-use (TOCTOU) condition. An attacker can exploit this flaw to copy instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.
lxd >= 5.0.0, < 5.0.8lxd >= 5.1, < 5.21.6lxd >= 6.0, < 6.9Upgrade past the affected range:
lxd 6.9Connected by shared product, vendor, weakness, or advisory.
CVE-2026-62420Critical· 9.9An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations
CVE-2026-63295Medium· 4.3An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions
CVE-2026-63296Critical· 9.9An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration
CVE-2026-9640High· 7.2A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration.
CVE-2026-66897Critical· 9.9A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root
CVE-2026-23950High· 8.8node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3