VDB

CVE-2026-55622

CVE-2026-55622 PUBLISHED CVSS 7.7 HIGH

Reported by GitHub_M · Published August 21, 2026

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in that project can copy the instance to a new project. This issue could allow an attacker to access secrets in instances they are not authorized to access. Version 7.2.0 patches the issue.

Risk Scores

CVSS 3.1
7.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Affected Products

VendorProductVersions
lxcincus< 7.2.0
alpineincus-feature0, 0, 0
alpineincus0, 0, 0
github.comlxc/incus/v7/cmd/incusd0
lxcincus< 7.2.0, < 7.2.0

Timeline

  • Aug 21, 2026 CVE Published
  • Aug 24, 2026 EPSS Score
  • Aug 28, 2026 CVE Updated
  • Aug 29, 2026 Security Advisory
  • Sep 6, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 17, 2026 EPSS Score
  • Sep 19, 2026 EPSS Score
  • Sep 24, 2026 EPSS Score
  • Sep 25, 2026 EPSS Score
  • Sep 26, 2026 EPSS Score
  • Sep 30, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›