No, it does not[1]. LXD:
- explicitly warns against this mode of vulnerability. Of course, there's no protection against people who blindly run commands copied from the internets, but the official documentation, at least, for as far back as I can recall, has had clear warning boxes against this, with explanations.
- does not have the track record of bad design that docker has had (IMO).
- supports fine-grained ACLs and user management.
----
[1]: https://ubuntu.com/blog/shared-development-environment-with-...
https://starlabs.sg/blog/2026/06-old-wine-in-a-new-bottle-a-...
And yes, I've tried it myself, it works as advertised.
I mean, this is a setup that ships with a default password that's the same as the username, and the first thing I do on all my server installs is disable all default user accounts and enable passwordless sudo.
From reading other docs of Ubuntu Server, it appears they relax the root/non-root distinction in other ways too. But I'd probably never have suspected this particular vector of vulnerability.