A vulnerability was found in Canonical LXD up to 5.0.7/5.21.5/6.9 . It has been classified as problematic . Impacted is the function storagePoolVolumeTypePostMove of the component Volume Operations . Performing a manipulation results in authorization bypass. This vulnerability was named CVE-2026-63299 . The attack may be initiated remotely. There is no available exploit. Upgrading the affected component is recommended.