High severity7.7NVD Advisory· Published Aug 21, 2026· Updated Sep 18, 2026
CVE-2026-55622
CVE-2026-55622
Description
Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in that project can copy the instance to a new project. This issue could allow an attacker to access secrets in instances they are not authorized to access. Version 7.2.0 patches the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/lxc/incus/v7/cmd/incusdGo | < 7.2.0 | 7.2.0 |
Affected products
3- osv-coords2 versionspkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/incus&distro=openSUSE%20Tumbleweed
< 0.0.20260902T191204-160000.1.1+ 1 more
- (no CPE)range: < 0.0.20260902T191204-160000.1.1
- (no CPE)range: < 7.4-1.1
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-c9f5-j9c3-mhrgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-55622ghsaADVISORY
- discuss.linuxcontainers.org/t/incus-7-2-has-been-released/26879ghsaWEB
- github.com/lxc/incus/commit/1e3ffc53a10950e55de62ac1e0d612be597b84ebghsaWEB
- github.com/lxc/incus/pull/3542ghsaWEB
- github.com/lxc/incus/releases/tag/v7.2.0ghsaWEB
- github.com/lxc/incus/security/advisories/GHSA-c9f5-j9c3-mhrgnvdWEB
News mentions
1- Incus: 18 Vulnerabilities Disclosed, Nine Critical, Allowing Root AccessVypr Intelligence · Aug 21, 2026