← Back to overview

CVE-2026-62867 affects Incus, a system container and virtual machine manager. Versions prior to 7.3.0 fail to properly validate user-supplied 'block.create_options' in storage volume configuration. This improper validation enables argument injection into the filesystem creation command line constructed by Incus. A project-scoped user can exploit this to inject arbitrary arguments into a binary executed with root privileges. The vulnerability represents a privilege escalation risk in multi-tenant or shared Incus environments. The issue has been patched in Incus version 7.3.0, and users are advised to upgrade immediately.

Affected products

  • Incus

Related CVE's

  • CVE-2026-62867

Categories

  • Cloud & Virtualization