← Terug naar overzicht

CVE-2026-62940 affects Incus, a system container and virtual machine manager, in versions prior to 7.3.0. The vulnerability exists in the instance migration process between cluster members, where user-supplied configuration overrides are applied without enforcing project restriction policies. Security-critical configuration keys such as `security.privileged` and `raw.lxc` can be manipulated by restricted project users during migration. This allows an attacker to escalate privileges to a privileged container and subsequently escape to the underlying host system. The flaw represents a container escape vulnerability with significant impact on multi-tenant cluster environments. Version 7.3.0 of Incus addresses and patches this issue. Users running Incus in clustered configurations with restricted project users are at elevated risk.

Affected products

  • Incus

Related CVE's

  • CVE-2026-62940

Categories

  • Cloud & Virtualization
  • Identity & Access