CVE-2026-55622 affects Incus, a system container and virtual machine manager, in versions prior to 7.2.0. The vulnerability stems from missing authorization checks during instance copying operations. An attacker who knows the name of a project and an instance within that project—even without authorized access—can copy the instance to a different project. This unauthorized copying could expose sensitive secrets stored within those instances. The flaw represents a significant access control bypass in multi-tenant or shared container environments. Version 7.2.0 of Incus has been released to patch this issue. Users are strongly advised to upgrade to mitigate unauthorized access risks.