CVE-2026-63300 – Canonical LXD

CVSS 9.9 CRITICAL Zero Day – Immediate Deployment

“Critical LXD flaws can break project isolation and turn crafted migrations or archives into host-level compromise.”

Canonical LXD is affected by ten vulnerabilities spanning authorization bypass, symlink handling, path traversal, configuration injection, and resource-limit enforcement. CVE-2026-62420, CVE-2026-63293, CVE-2026-63294, CVE-2026-63296, CVE-2026-63297, CVE-2026-63300, and CVE-2026-66898 each have a CVSS score of 9.9, Critical severity. These flaws can bypass project restrictions, enable arbitrary host file access or modification, and, in the case of CVE-2026-63294, lead to root command execution.

CVE-2026-16033 and CVE-2026-63299 each have a CVSS score of 8.5, High severity. CVE-2026-63298 has a CVSS score of 8.7, High severity and can enable arbitrary code execution with LXD daemon privileges. Public proof-of-concept information is available for CVE-2026-63293, CVE-2026-63294, CVE-2026-63296, CVE-2026-63297, CVE-2026-63300, CVE-2026-66898, CVE-2026-16033, and CVE-2026-63298.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-862
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.