Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-63296

Опубликовано: 12 авг. 2026
Источник: debian
EPSS Низкий

Описание

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. An attacker can exploit this flaw to move instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lxdremovedpackage
lxdend-of-lifebookwormpackage

Примечания

  • https://github.com/canonical/lxd/security/advisories/GHSA-gcr9-5q6r-w625

EPSS

Процентиль: 16%
0.00246
Низкий

Связанные уязвимости

CVSS3: 9.9
ubuntu
22 дня назад

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. An attacker can exploit this flaw to move instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.

CVSS3: 9.9
nvd
22 дня назад

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. An attacker can exploit this flaw to move instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.

EPSS

Процентиль: 16%
0.00246
Низкий