CVE-2026-63298 – Canonical LXD
“Critical LXD flaws can break project isolation and turn crafted migrations or archives into host-level compromise.”
Canonical LXD is affected by ten vulnerabilities spanning authorization bypass, symlink handling, path traversal, configuration injection, and resource-limit enforcement. CVE-2026-62420, CVE-2026-63293, CVE-2026-63294, CVE-2026-63296, CVE-2026-63297, CVE-2026-63300, and CVE-2026-66898 each have a CVSS score of 9.9, Critical severity. These flaws can bypass project restrictions, enable arbitrary host file access or modification, and, in the case of CVE-2026-63294, lead to root command execution.
CVE-2026-16033 and CVE-2026-63299 each have a CVSS score of 8.5, High severity. CVE-2026-63298 has a CVSS score of 8.7, High severity and can enable arbitrary code execution with LXD daemon privileges. Public proof-of-concept information is available for CVE-2026-63293, CVE-2026-63294, CVE-2026-63296, CVE-2026-63297, CVE-2026-63300, CVE-2026-66898, CVE-2026-16033, and CVE-2026-63298.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-78