Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to LXD version 4.0.12 or later, 5.0.8 or later, or 5.12.6 or later, or 6.10 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 12 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical lxd |
|
| Vendors & Products |
Canonical
Canonical lxd |
Wed, 12 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as enforcing restricted.containers.privilege=isolated), LXD fails to enforce the requirement if an instance configuration omits the security.idmap.isolated key. An attacker can exploit this flaw by creating or updating an instance without explicitly setting security.idmap.isolated, bypassing the target project's security constraints. | |
| Title | Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated` | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-08-12T19:31:32.323Z
Reserved: 2026-07-16T09:49:29.911Z
Link: CVE-2026-63295
No data.
Status : Received
Published: 2026-08-12T20:17:47.303
Modified: 2026-08-12T20:17:47.303
Link: CVE-2026-63295
No data.
OpenCVE Enrichment
Updated: 2026-08-12T20:45:08Z