← Terug naar overzicht

CVE-2026-55621 affects Incus, a system container and virtual machine manager, in versions prior to 7.2.0. The vulnerability involves missing authorization checks during custom volume copying operations. An attacker who knows the name of a project and a custom volume within that project can copy the volume to a different project without proper authorization. This flaw could allow unauthorized access to sensitive secrets stored in custom volumes. The attack requires knowledge of valid project and volume names but does not require authenticated access to those resources. The issue has been patched in Incus version 7.2.0. Users are advised to upgrade immediately to mitigate the risk of unauthorized data access.

Affected products

  • Incus

Related CVE's

  • CVE-2026-55621

Categories

  • Cloud & Virtualization
  • Identity & Access