CVE-2026-92761
Last modified
CVE-2026-92761 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only users to perform privileged actions. Attackers with read-only grants can power off virtual machines, reset root passwords, install SSH keys, and manage ISO images by exploiting the get_instance gate that only checks grant existence..
Description
WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only users to perform privileged actions. Attackers with read-only grants can power off virtual machines, reset root passwords, install SSH keys, and manage ISO images by exploiting the get_instance gate that only checks grant existence.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| retspen | webvirtcloud | 1b2da68b2800f94674dd96f4a986cde30ac88280 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-92761?
How severe is CVE-2026-92761?
How do I fix CVE-2026-92761?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-92754PatrowlManager through 1.8.4 contains an improper access con…4.3
- CVE-2026-92756Applications built on MongoDB Entity Framework Core Provider…5.5
- CVE-2026-92757Applications built on MongoDB Entity Framework Core Provider…5.5
- CVE-2026-92758If logging mode is set to DEBUG or a malformed MongoDB conne…5.5
- CVE-2026-92759SecObserve versions before 1.59.1 contain an information dis…6.5
- CVE-2026-92760Shlink through 5.1.6 fails to enforce API key role restricti…6.5
- CVE-2026-92762Pelican Panel versions before 1.0.0-beta35 enforce startup w…8.8
- CVE-2026-92763Rundeck through 6.2.1 fails to properly authorize the import…8.1
- CVE-2026-92764OpenCVE before 3.1.0 fails to properly scope the organizatio…4.3
- CVE-2026-92765ArcherySec through 2.0.6 fails to validate organization owne…6.5
- CVE-2026-92768A flaw was found in cockpit-machines. This vulnerability all…5.5
- CVE-2026-9277shell-quote's `quote()` function did not validate object-tok…8.1
Are you affected by CVE-2026-92761?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
