{"api_version":"1","generated_at":"2026-09-29T04:32:26+00:00","cve":"CVE-2026-63295","urls":{"html":"https://cve.report/CVE-2026-63295","api":"https://cve.report/api/cve/CVE-2026-63295.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-63295","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-63295"},"summary":{"title":"Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated`","description":"An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as enforcing restricted.containers.privilege=isolated), LXD fails to enforce the requirement if an instance configuration omits the security.idmap.isolated key. An attacker can exploit this flaw by creating or updating an instance without explicitly setting security.idmap.isolated, bypassing the target project's security constraints.","state":"PUBLISHED","assigner":"canonical","published_at":"2026-08-12 20:17:47","updated_at":"2026-09-11 15:13:26"},"problem_types":["CWE-863","CWE-863 CWE-863 Incorrect Authorization"],"metrics":[{"version":"3.1","source":"security@ubuntu.com","type":"Secondary","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","version":"3.1"}}],"references":[{"url":"https://github.com/canonical/lxd/security/advisories/GHSA-7vp9-3vmp-c5jm","name":"https://github.com/canonical/lxd/security/advisories/GHSA-7vp9-3vmp-c5jm","refsource":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Vendor Advisory","Exploit"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-63295","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63295","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Canonical","product":"LXD","version":"affected 4.0.0 4.0.12 semver","platforms":["Linux"]},{"source":"CNA","vendor":"Canonical","product":"LXD","version":"affected 5.0.0 5.0.8 semver","platforms":["Linux"]},{"source":"CNA","vendor":"Canonical","product":"LXD","version":"affected 5.21.0 5.21.6 semver","platforms":["Linux"]},{"source":"CNA","vendor":"Canonical","product":"LXD","version":"affected 6.0 6.10 semver","platforms":["Linux"]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Upgrade to LXD version 4.0.12 or later, 5.0.8 or later, or 5.12.6 or later, or 6.10 or later.","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2026","cve_id":"63295","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"canonical","cpe5":"lxd","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"63295","cve":"CVE-2026-63295","epss":"0.002130000","percentile":"0.114680000","score_date":"2026-08-30","updated_at":"2026-08-31 00:14:06"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-63295","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-08-13T14:23:43.547083Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-08-13T14:24:15.556Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"references":[{"tags":["exploit"],"url":"https://github.com/canonical/lxd/security/advisories/GHSA-7vp9-3vmp-c5jm"}],"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","packageName":"LXD","platforms":["Linux"],"product":"LXD","repo":"https://github.com/canonical/lxd","vendor":"Canonical","versions":[{"lessThan":"4.0.12","status":"affected","version":"4.0.0","versionType":"semver"},{"lessThan":"5.0.8","status":"affected","version":"5.0.0","versionType":"semver"},{"lessThan":"5.21.6","status":"affected","version":"5.21.0","versionType":"semver"},{"lessThan":"6.10","status":"affected","version":"6.0","versionType":"semver"}]}],"descriptions":[{"lang":"en","value":"An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as enforcing restricted.containers.privilege=isolated), LXD fails to enforce the requirement if an instance configuration omits the security.idmap.isolated key. An attacker can exploit this flaw by creating or updating an instance without explicitly setting security.idmap.isolated, bypassing the target project's security constraints."}],"impacts":[{"capecId":"CAPEC-1","descriptions":[{"lang":"en","value":"Accessing Functionality Not Properly Constrained by ACLs"}]},{"capecId":"CAPEC-122","descriptions":[{"lang":"en","value":"Privilege Abuse"}]},{"capecId":"CAPEC-233","descriptions":[{"lang":"en","value":"Privilege Escalation"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-863","description":"CWE-863 Incorrect Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-12T19:31:32.323Z","orgId":"cc1ad9ee-3454-478d-9317-d3e869d708bc","shortName":"canonical"},"references":[{"tags":["vdb-entry","vendor-advisory"],"url":"https://github.com/canonical/lxd/security/advisories/GHSA-7vp9-3vmp-c5jm"}],"solutions":[{"lang":"en","value":"Upgrade to LXD version 4.0.12 or later, 5.0.8 or later, or 5.12.6 or later, or 6.10 or later."}],"source":{"discovery":"EXTERNAL"},"title":"Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated`"}},"cveMetadata":{"assignerOrgId":"cc1ad9ee-3454-478d-9317-d3e869d708bc","assignerShortName":"canonical","cveId":"CVE-2026-63295","datePublished":"2026-08-12T19:31:32.323Z","dateReserved":"2026-07-16T09:49:29.911Z","dateUpdated":"2026-08-13T14:24:15.556Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-12 20:17:47","lastModifiedDate":"2026-09-11 15:13:26","problem_types":["CWE-863","CWE-863 CWE-863 Incorrect Authorization"],"metrics":{"cvssMetricV31":[{"source":"security@ubuntu.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-13T14:23:43.547083Z","id":"CVE-2026-63295","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0.0","versionEndExcluding":"4.0.12","matchCriteriaId":"89DC62EE-69CD-4ACD-BB83-6A0635AC341C"},{"vulnerable":true,"criteria":"cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0.0","versionEndExcluding":"5.0.8","matchCriteriaId":"59D070D6-84D2-400E-8260-EA52E5C60D37"},{"vulnerable":true,"criteria":"cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*","versionStartIncluding":"5.1","versionEndExcluding":"5.21.6","matchCriteriaId":"575036D1-2B55-4043-B94A-1584E3F2DA37"},{"vulnerable":true,"criteria":"cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.10","matchCriteriaId":"374F5622-1D8F-4EF9-97E6-736C8220623B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"63295","Ordinal":"1","Title":"Project restriction `restricted.containers.privilege=isolated` b","CVE":"CVE-2026-63295","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"63295","Ordinal":"1","NoteData":"An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as enforcing restricted.containers.privilege=isolated), LXD fails to enforce the requirement if an instance configuration omits the security.idmap.isolated key. An attacker can exploit this flaw by creating or updating an instance without explicitly setting security.idmap.isolated, bypassing the target project's security constraints.","Type":"Description","Title":"Project restriction `restricted.containers.privilege=isolated` b"}]}}}