๐Ÿ” CVE Alert

CVE-2026-92761

HIGH 8.8

WebVirtCloud Missing Authorization on Instance Control Actions

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only users to perform privileged actions. Attackers with read-only grants can power off virtual machines, reset root passwords, install SSH keys, and manage ISO images by exploiting the get_instance gate that only checks grant existence.

CWE CWE-862
Vendor retspen
Product webvirtcloud
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for retspen webvirtcloud

Be the first to know when new high vulnerabilities affecting retspen webvirtcloud are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

retspen / webvirtcloud
1b2da68b2800f94674dd96f4a986cde30ac88280

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/retspen/webvirtcloud/issues/682 github.com: https://github.com/retspen/webvirtcloud github.com: https://github.com/retspen/webvirtcloud/blob/1b2da68b2800f94674dd96f4a986cde30ac88280/instances/views.py#L316-L330 github.com: https://github.com/retspen/webvirtcloud/blob/1b2da68b2800f94674dd96f4a986cde30ac88280/instances/views.py#L356-L363 github.com: https://github.com/retspen/webvirtcloud/blob/1b2da68b2800f94674dd96f4a986cde30ac88280/instances/views.py#L538-L546 vulncheck.com: https://www.vulncheck.com/advisories/webvirtcloud-missing-authorization-on-instance-control-actions

Credits

George Chen