๐Ÿ” CVE Alert

CVE-2026-55621

HIGH 7.7

Incus has a project restriction bypass for custom volume copy across projects

CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the name of a custom volume in that project can copy the custom volume to a new project. This issue could allow an attacker to access secrets in custom volumes they are not authorized to access. Version 7.2.0 patches the issue.

CWE CWE-284
Vendor lxc
Product incus
Published Aug 21, 2026
Stay Ahead of the Next One

Get instant alerts for lxc incus

Be the first to know when new high vulnerabilities affecting lxc incus are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

lxc / incus
< 7.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/lxc/incus/security/advisories/GHSA-64f3-v33m-w89f