High severity7.7NVD Advisory· Published Aug 21, 2026· Updated Sep 18, 2026
CVE-2026-55621
CVE-2026-55621
Description
Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the name of a custom volume in that project can copy the custom volume to a new project. This issue could allow an attacker to access secrets in custom volumes they are not authorized to access. Version 7.2.0 patches the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/lxc/incus/v7Go | < 7.2.0 | 7.2.0 |
github.com/lxc/incus/v6Go | <= 6.23.0 | — |
github.com/lxc/incusGo | <= 0.7.0 | — |
Affected products
3- osv-coords2 versionspkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/incus&distro=openSUSE%20Tumbleweed
< 0.0.20260902T191204-160000.1.1+ 1 more
- (no CPE)range: < 0.0.20260902T191204-160000.1.1
- (no CPE)range: < 7.4-1.1
Patches
Vulnerability mechanics
References
5News mentions
1- Incus: 18 Vulnerabilities Disclosed, Nine Critical, Allowing Root AccessVypr Intelligence · Aug 21, 2026