VDB

CVE-2026-63295

CVE-2026-63295 PUBLISHED CVSS 4.3 MEDIUM

Reported by canonical · Published August 12, 2026

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as enforcing restricted.containers.privilege=isolated), LXD fails to enforce the requirement if an instance configuration omits the security.idmap.isolated key. An attacker can exploit this flaw by creating or updating an instance without explicitly setting security.idmap.isolated, bypassing the target project's security constraints.

Risk Scores

CVSS 3.1
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Affected Products

VendorProductVersions
CanonicalLXD4.0.0, 5.0.0, 5.21.0
CanonicalLXD4.0.0, 5.0.0, 5.21.0

Timeline

  • Aug 12, 2026 CVE Published
  • Aug 13, 2026 Coalition ESS Score
  • Aug 20, 2026 Security Advisory
  • Aug 24, 2026 EPSS Score
  • Sep 5, 2026 EPSS Score
  • Sep 11, 2026 CVE Updated
  • Sep 12, 2026 EPSS Score
  • Sep 17, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
  • Sep 24, 2026 EPSS Score
  • Sep 26, 2026 EPSS Score
  • Sep 30, 2026 EPSS Score

References

  • vdb-entryvendor-advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›