Critical severity9.9NVD Advisory· Published Aug 21, 2026· Updated Sep 18, 2026
CVE-2026-62941
CVE-2026-62941
Description
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (AllowInstanceCreation) runs BEFORE the source instance's configuration is merged into the request. Dangerous configuration keys (including security.privileged, raw.lxc, raw.apparmor) from the source instance are merged AFTER the check passes, bypassing all project restrictions on the target project. Version 7.3.0 patches the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
1News mentions
1- Incus: 18 Vulnerabilities Disclosed, Nine Critical, Allowing Root AccessVypr Intelligence · Aug 21, 2026