CVE-2026-63295

Source
https://cve.org/CVERecord?id=CVE-2026-63295
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63295.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63295
Aliases
  • GHSA-7vp9-3vmp-c5jm
Downstream
Published
2026-08-12T19:31:32.323Z
Modified
2026-08-15T11:31:06.651705313Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated`
Details

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as enforcing restricted.containers.privilege=isolated), LXD fails to enforce the requirement if an instance configuration omits the security.idmap.isolated key. An attacker can exploit this flaw by creating or updating an instance without explicitly setting security.idmap.isolated, bypassing the target project's security constraints.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "6.0"
                },
                {
                    "fixed": "6.10"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cna_assigner": "canonical",
    "cwe_ids": [
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63295.json"
}
References

Affected packages

Git / github.com/canonical/lxd

Affected ranges

Type
GIT
Repo
https://github.com/canonical/lxd
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "4.0.0"
        },
        {
            "fixed": "4.0.12"
        },
        {
            "introduced": "5.0.0"
        },
        {
            "fixed": "5.0.8"
        },
        {
            "introduced": "5.21.0"
        },
        {
            "fixed": "5.21.6"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

lxd-4.*
lxd-4.0.0
lxd-4.0.1
lxd-4.0.11
lxd-4.0.2
lxd-4.0.3
lxd-4.0.4
lxd-4.0.5
lxd-4.0.6
lxd-4.0.7
lxd-4.0.8
lxd-4.0.9
lxd-5.*
lxd-5.0.0
lxd-5.0.1
lxd-5.0.2
lxd-5.0.7
lxd-5.1
lxd-5.10
lxd-5.11
lxd-5.12
lxd-5.13
lxd-5.14
lxd-5.15
lxd-5.16
lxd-5.17
lxd-5.2
lxd-5.21.5
lxd-5.3
lxd-5.4
lxd-5.5
lxd-5.6
lxd-5.7
lxd-5.8
lxd-5.9
Other
show

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63295.json"