What is CVE-2026-62420?
An authorization bypass vulnerability in LXD allows an authenticated attacker to circumvent target project security restrictions during cross-project instance migrations. To mitigate the risk, it is recommended to update LXD to the latest patched version and monitor for suspicious migration activities.
Azərbaycanca: LXD-də aşkar edilmiş bu icazə yan keçmə zəifliyi (Authorization Bypass) autentifikasiya olunmuş hücumçuya layihələrarası instansiya köçürmələri zamanı hədəf layihənin təhlükəsizlik məhdudiyyətlərini keçməyə imkan verir. Təsirə məruz qalmamaq üçün LXD-ni ən son versiyaya yeniləmək və şübhəli köçürmə əməliyyatlarını nəzarətdə saxlamaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Does exploiting CVE-2026-62420 require the attacker to be authenticated?
Yes, this authorization bypass vulnerability can only be exploited by an authenticated attacker.
During which operation in LXD does this vulnerability occur?
The vulnerability occurs during cross-project instance migrations, allowing bypass of the target project's security restrictions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.