CVE-2026-62420
Last modified
CVE-2026-62420 is a critical-severity vulnerability rated 9.9/10 on the CVSS scale. An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: <target>, and target: <member>, the destination node skips all project restriction checks because the request arrives as an internal cluster notification.
Description
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: <target>, and target: <member>, the destination node skips all project restriction checks because the request arrives as an internal cluster notification. An attacker can exploit this to introduce disallowed instance configurations into a restricted project.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Canonical | LXD | >= 5.0.0, < 5.0.8; >= 5.21.0, < 5.21.6; >= 6.0, < 6.10 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-62420?
How severe is CVE-2026-62420?
How do I fix CVE-2026-62420?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-6241An authenticated format string vulnerability is present in t…6.8
- CVE-2026-62414Joomla Extension - joomlack.fr - Improper access control in …9.1
- CVE-2026-62415Joomla Extension - joomdonation.com - Insecure default confi…9.1
- CVE-2026-62416Network Scanner Tool and Network Scanner Tool Lite provided …6.9
- CVE-2026-62418Low-privileged authenticated Server-Side Request Forgery (SS…8.1
- CVE-2026-6242An authenticated format string vulnerability exists in the O…6.8
- CVE-2026-62421Rejected reason: Voluntarily withdrawn
- CVE-2026-62422In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 20…9.8
- CVE-2026-62423[This CNA information record relates to multiple CVEs; the t…5.5
- CVE-2026-62424[This CNA information record relates to multiple CVEs; the t…5.5
- CVE-2026-62425[This CNA information record relates to multiple CVEs; the t…5.5
- CVE-2026-62426[This CNA information record relates to multiple CVEs; the t…8.8
Are you affected by CVE-2026-62420?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
