Critical severity9.9NVD Advisory· Published Aug 21, 2026· Updated Sep 18, 2026
CVE-2026-62940
CVE-2026-62940
Description
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (including security-critical keys like security.privileged and raw.lxc) are applied without any project restriction enforcement, allowing a restricted project user to escalate to a privileged container and escape to the host. Version 7.3.0 patches the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
1News mentions
1- Incus: 18 Vulnerabilities Disclosed, Nine Critical, Allowing Root AccessVypr Intelligence · Aug 21, 2026