Description
Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in that project can copy the instance to a new project. This issue could allow an attacker to access secrets in instances they are not authorized to access. Version 7.2.0 patches the issue.
Published: 2026-08-21
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Incus, a system container and virtual machine manager, had a missing authorization check that allowed an attacker who knows the name of a project and an instance inside that project to copy the instance into a new project. This flaw is a classic permission‑bypass (CWE‑284), enabling the attacker to obtain secrets and configuration data from instances they should not be able to view. The impact is therefore the unauthorized exposure of sensitive data and a pathway to privilege escalation within the Incus environment.

Affected Systems

All releases of Incus prior to version 7.2.0 are affected. The product is identified by the vendor product pair lxc:incus. Users running any 7.1.x or earlier release should consider themselves vulnerable.

Risk and Exploitability

The CVSS score of 7.7 indicates a high severity vulnerability. No EPSS score is available, but the absence of a KEV listing suggests that known exploits are not publicly documented yet. The likely attack vector is through authenticated API or command usage, where an attacker with at least legitimate user access can supply the target project and instance names to trigger the copy. Because the flaw bypasses authorization on the copy operation, a malicious user could elevate their privileges within the container ecosystem by accessing data in other projects.

Generated by OpenCVE AI on August 21, 2026 at 16:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch that upgrades Incus to version 7.2.0 or later.
  • Revoke or limit permissions that allow users to copy instances across projects, ensuring that only authorized administrators retain that capability.
  • Audit existing project permissions and instance copy activities to verify no unauthorized operations have occurred.
  • If the patch cannot be applied immediately, monitor for anomalous copy operations and enforce the principle of least privilege on a temporary basis.

Generated by OpenCVE AI on August 21, 2026 at 16:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6370-1 incus security update
Debian DSA Debian DSA DSA-6373-1 lxd security update
History

Fri, 21 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Lxc
Lxc incus
Vendors & Products Lxc
Lxc incus

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Description Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in that project can copy the instance to a new project. This issue could allow an attacker to access secrets in instances they are not authorized to access. Version 7.2.0 patches the issue.
Title Incus has a project restriction bypass in instance copy across projects
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-21T15:35:57.698Z

Reserved: 2026-06-16T23:31:22.446Z

Link: CVE-2026-55622

cve-icon Vulnrichment

Updated: 2026-08-21T15:35:42.413Z

cve-icon NVD

Status : Received

Published: 2026-08-21T15:16:42.003

Modified: 2026-08-21T16:17:19.623

Link: CVE-2026-55622

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T16:30:06Z

Weaknesses