CVE-2026-55622
Last modified
CVE-2026-55622 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in that project can copy the instance to a new project. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in that project can copy the instance to a new project. This issue could allow an attacker to access secrets in instances they are not authorized to access. Version 7.2.0 patches the issue.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| lxc | incus | < 7.2.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-55622?
How severe is CVE-2026-55622?
How do I fix CVE-2026-55622?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-55617Hydro is a next-generation high-performance online judge pla…6.9
- CVE-2026-55618eml_parser serves as a python module for parsing eml files a…6.5
- CVE-2026-55619eml_parser serves as a python module for parsing eml files a…5.3
- CVE-2026-5562A vulnerability was identified in provectus kafka-ui up to 0…9.8
- CVE-2026-55620eml_parser serves as a python module for parsing eml files a…7.5
- CVE-2026-55621Incus is a system container and virtual machine manager. Pri…7.7
- CVE-2026-55623Rejected reason: This CVE is a duplicate of another CVE.
- CVE-2026-55624MintyItanium Lost-Auction is an auction plugin for Minecraft…5.3
- CVE-2026-55625GoCD is a continuous deliver server. From 16.1.0 until 26.1.…4.9
- CVE-2026-55626xrdp is an open source RDP server. In versions 0.10.6 and pr…7.3
- CVE-2026-55628ImageMagick is free and open-source software used for editin…5.5
- CVE-2026-55629Whistle is an HTTP, HTTP2, HTTPS, and WebSocket debugging pr…8.7
Are you affected by CVE-2026-55622?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
