CVE-2026-55622

EUVD-2026-63985
Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in that project can copy the instance to a new project. This issue could allow an attacker to access secrets in instances they are not authorized to access. Version 7.2.0 patches the issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.7 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Debian logo
Debian Releases
Debian Product
Codename
incus
forky
7.0.1-2
fixed
sid
7.0.1-2
fixed
trixie
6.0.4-2+deb13u8
fixed
trixie (security)
6.0.4-2+deb13u9
fixed
lxd
bookworm
vulnerable
bookworm (security)
vulnerable
trixie
5.0.2+git20231211.1364ae4-9+deb13u7
fixed
trixie (security)
5.0.2+git20231211.1364ae4-9+deb13u7
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
incus
jammy
dne
noble
needs-triage
questing
ignored
resolute
needs-triage
lxd
bionic
needs-triage
focal
needs-triage
jammy
dne
noble
dne
questing
dne
resolute
dne
xenial
needs-triage