Description
Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the name of a custom volume in that project can copy the custom volume to a new project. This issue could allow an attacker to access secrets in custom volumes they are not authorized to access. Version 7.2.0 patches the issue.
Published: 2026-08-21
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Incus contains an authorization flaw that allows a user who knows the name of a project and a custom volume within that project to copy the volume into a new project, even when the user has no access rights to the source project. This bypass can expose secrets stored in the volume and compromise data confidentiality. The weakness is a classic denial of authorization condition, reflected by CWE-284.

Affected Systems

All Incus installations running a version prior to 7.2.0 are vulnerable. The issue was fixed in Incus 7.2.0, which restores proper project access controls for custom volume copy operations.

Risk and Exploitability

The CVSS score of 7.7 indicates high severity. The exploitability requires the attacker to know the exact project and volume names and to have the ability to invoke the Incus API or command‑line interface. Because the CI or API must be reachable, the attack vector is likely local or over an untrusted network connection to the Incus daemon, which limits exposure to environments where such access is possible. No known public exploits are listed; the vulnerability is not yet included in CISA’s KEV catalog and EPSS data is unavailable.

Generated by OpenCVE AI on August 21, 2026 at 16:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Incus version 7.2.0 or later to receive the authorisation fix
  • Restrict access to the Incus API and CLI to trusted users or machines, ensuring that only authorized personnel can invoke volume copy operations
  • If an immediate upgrade is not possible, disable or limit the custom volume copy feature through configuration until the patch can be applied

Generated by OpenCVE AI on August 21, 2026 at 16:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6370-1 incus security update
Debian DSA Debian DSA DSA-6373-1 lxd security update
History

Fri, 21 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Lxc
Lxc incus
Vendors & Products Lxc
Lxc incus

Fri, 21 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Description Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the name of a custom volume in that project can copy the custom volume to a new project. This issue could allow an attacker to access secrets in custom volumes they are not authorized to access. Version 7.2.0 patches the issue.
Title Incus has a project restriction bypass for custom volume copy across projects
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-21T16:41:23.236Z

Reserved: 2026-06-16T23:31:22.446Z

Link: CVE-2026-55621

cve-icon Vulnrichment

Updated: 2026-08-21T16:41:18.602Z

cve-icon NVD

Status : Received

Published: 2026-08-21T15:16:41.863

Modified: 2026-08-21T17:16:31.800

Link: CVE-2026-55621

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T17:00:03Z

Weaknesses