Improper access control in LXD - CVE-2026-63296
Published: August 1, 2026
LXD
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code on the host as root.
The vulnerability exists due to improper access control in the instance migration handler when applying user-supplied configuration overrides during cross-member instance migration. A remote user can send a specially crafted instance migration request to execute arbitrary code on the host as root.
Exploitation requires a clustered deployment with 2 or more members and an instance in a restricted project.