PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-55622 lxc CVE debrief

The Incus system container and virtual machine manager has a vulnerability in versions prior to 7.2.0, allowing instance copying without authorization checks. This could enable an attacker to access secrets in instances they are not authorized to access. The vulnerability exists due to missing authorization checks when copying instances between projects. An attacker knowing the name of a project they don't have access to and the name of an instance in that project can copy the instance to a new project, potentially gaining access to sensitive information. Instances with sensitive data should be reviewed for unauthorized access, and administrators should verify that Incus version 7.2.0 or later is deployed. Evidence is limited to NVD and CVE.org records. Further verification is needed to confirm affected deployments and assess potential impact. Defenders should review instance configurations, verify access controls, and monitor for suspicious activity related to instance copying. The CVE record was published on 2026-08-21T15:16:42.003Z and has not been modified since then. AI-assisted PatchSiren debrief based on the supplied source corpus.

Vendor
lxc
Product
incus
CVSS
HIGH 7.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-08-21
Advisory published
2026-08-21
Advisory updated
2026-08-21

Who should care

Administrators and users of Incus versions prior to 7.2.0, especially those with sensitive data in instances, should be aware of this vulnerability. Operators managing Incus deployments, security teams responsible for vulnerability management, and platform administrators should prioritize patching to version 7.2.0 or later. Additionally, those responsible for monitoring and incident response should be prepared to detect and respond to potential exploitation attempts related to this vulnerability.

Technical summary

The Incus system container and virtual machine manager has a vulnerability in versions prior to 7.2.0, allowing instance copying without authorization checks. This could enable an attacker to access secrets in instances they are not authorized to access. The vulnerability exists due to missing authorization checks when copying instances between projects. An attacker knowing the name of a project they don't have access to and the name of an instance in that project can copy the instance to a new project, potentially gaining access to sensitive information.

Defensive priority

Instances with sensitive data should be reviewed for unauthorized access, and administrators should verify that Incus version 7.2.0 or later is deployed.

Recommended defensive actions

  • Verify Incus version and upgrade to 7.2.0 or later
  • Review instances for unauthorized access
  • Monitor for suspicious activity
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record indicates that Incus versions prior to 7.2.0 have a vulnerability allowing instance copying without authorization checks, potentially exposing secrets. Evidence is limited to NVD and CVE.org records. Further verification is needed to confirm affected deployments and assess potential impact. Defenders should review instance configurations, verify access controls, and monitor for suspicious activity related to instance copying.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T15:16:42.003Z and has not been modified since then.