← Back to overview

CVE-2026-62941 affects Incus, a system container and virtual machine manager, in versions prior to 7.3.0. The vulnerability exists in the cross-project instance copy workflow, where the project restriction check (AllowInstanceCreation) runs before the source instance configuration is merged into the request. This timing flaw allows dangerous configuration keys such as security.privileged, raw.lxc, and raw.apparmor to be injected into the target project after the security check has already passed. As a result, all project-level restrictions on the target project are effectively bypassed. An attacker with access to copy instances across projects could exploit this to escalate privileges or escape container isolation. The issue has been patched in Incus version 7.3.0. Users are advised to upgrade immediately to mitigate the risk.

Affected products

  • Incus

Related CVE's

  • CVE-2026-62941

Categories

  • Cloud & Virtualization
  • Identity & Access