What is CVE-2026-63295?
CVE-2026-63295 is an authorization bypass vulnerability in LXD that allows an authenticated attacker to circumvent project-level container isolation restrictions. This specifically affects configurations where container privilege restrictions like `restricted.containers.privilege=isolated` are enforced but not properly applied by LXD. Updates to the latest LXD version are recommended to mitigate this issue.
Azərbaycanca: CVE-2026-63295 LXD platformasında aşkarlanan səlahiyyət bypass zəifliyidir. Bu zəiflik autentifikasiya olunmuş təcavüzkarın layihə səviyyəsində təyin olunmuş konteyner izolyasiya məhdudiyyətlərini (məsələn, `restricted.containers.privilege=isolated` parametri) keçməsinə imkan yaradır. Təsirə məruz qalan sistemlərdə LXD-ni ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Does exploiting CVE-2026-63295 require authentication?
Yes, this vulnerability can only be exploited by an authenticated attacker.
What type of configuration restriction does CVE-2026-63295 allow an attacker to bypass?
This vulnerability allows bypassing project-level container isolation restrictions, such as the `restricted.containers.privilege=isolated` parameter.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.