High severity8.8NVD Advisory· Published Sep 16, 2026
CVE-2026-92761
CVE-2026-92761
Description
WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only users to perform privileged actions. Attackers with read-only grants can power off virtual machines, reset root passwords, install SSH keys, and manage ISO images by exploiting the get_instance gate that only checks grant existence.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)
Patches
Vulnerability mechanics
References
5- github.com/retspen/webvirtcloud/blob/1b2da68b2800f94674dd96f4a986cde30ac88280/instances/views.pynvd
- github.com/retspen/webvirtcloud/blob/1b2da68b2800f94674dd96f4a986cde30ac88280/instances/views.pynvd
- github.com/retspen/webvirtcloud/blob/1b2da68b2800f94674dd96f4a986cde30ac88280/instances/views.pynvd
- github.com/retspen/webvirtcloud/issues/682nvd
- www.vulncheck.com/advisories/webvirtcloud-missing-authorization-on-instance-control-actionsnvd
News mentions
0No linked articles in our index yet.