Critical severity9.9NVD Advisory· Published Aug 21, 2026
CVE-2026-62941
CVE-2026-62941
Description
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (AllowInstanceCreation) runs BEFORE the source instance's configuration is merged into the request. Dangerous configuration keys (including security.privileged, raw.lxc, raw.apparmor) from the source instance are merged AFTER the check passes, bypassing all project restrictions on the target project. Version 7.3.0 patches the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.