CVE-2026-63299: Storage volume cross-project move and snapshot restore bypass project disk limits
An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations: the storagePoolVolumeTypePostMove function omits the limits.AllowVolumeCreation check before moving a volume across projects, and volume snapshot restore operations skip the AllowVolumeUpdate check when the configuration is nil (Config == nil). An attacker can exploit these flaws to allocate storage resources that exceed the administrative limits configured for a project.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
LXDto a version that resolves this vulnerability.Fixed in 5.0.8 - Upgrade
Upgrade
LXDto a version that resolves this vulnerability.Fixed in 5.21.6 - Upgrade
Upgrade
LXDto a version that resolves this vulnerability.Fixed in 6.10
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63299?
CVE-2026-63299 has a high severity score of 8.5.
How do I fix CVE-2026-63299?
To fix CVE-2026-63299, you should update your Canonical LXD software to the latest version that addresses this vulnerability.
What are the implications of CVE-2026-63299?
CVE-2026-63299 allows authenticated users to bypass project-level disk and volume limits, potentially leading to resource exhaustion.
Which software is affected by CVE-2026-63299?
CVE-2026-63299 affects Canonical LXD.
When was CVE-2026-63299 published?
CVE-2026-63299 was published on August 12, 2026.