CVE-2026-62420: Cross-project cluster migration bypasses project restrictions via cluster notification flag
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: <target>, and target: <member>, the destination node skips all project restriction checks because the request arrives as an internal cluster notification. An attacker can exploit this to introduce disallowed instance configurations into a restricted project.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
LXDto a version that resolves this vulnerability.Fixed in 5.0.8 - Upgrade
Upgrade
LXDto a version that resolves this vulnerability.Fixed in 5.21.6 - Upgrade
Upgrade
LXDto a version that resolves this vulnerability.Fixed in 6.10
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62420?
The severity of CVE-2026-62420 is critical with a score of 9.9.
What does CVE-2026-62420 allow an attacker to do?
CVE-2026-62420 allows an authenticated attacker to bypass project security restrictions during cross-project instance migrations.
How can I protect my systems from CVE-2026-62420?
To protect your systems from CVE-2026-62420, ensure that you implement strict access controls and monitor for unauthorized migration attempts.
Which software is affected by CVE-2026-62420?
CVE-2026-62420 affects Canonical LXD.
When was CVE-2026-62420 published?
CVE-2026-62420 was published on August 12, 2026.