PatchSiren cyber security CVE debrief
CVE-2026-62313 lxc CVE debrief
The Incus system container and virtual machine manager, prior to version 7.3.0, has a vulnerability (CVE-2026-62313) where project-level enforcement of `restricted.containers.privilege=isolated` can be bypassed. This allows users to create non-isolated containers, sharing the host uid/gid map instead of receiving unique, non-overlapping ranges. This weakness in isolation boundary between co-tenant containers and the host can have significant operational impact. The vulnerability's source-confidence limits are based on the official CVE record and NVD details. A review of the official advisory is necessary for further context. Users should verify their deployments and plan for updates or mitigations through normal change control.
- Vendor
- lxc
- Product
- incus
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-08-21
Who should care
Users of Incus system container and virtual machine manager, especially those with multi-tenant environments, should be aware of this vulnerability and take steps to update and secure their deployments. Affected operators, platforms, and security teams should review the official advisory and plan for updates or mitigations through normal change control. Monitoring and detection should be reviewed for exposed assets that need extra review. Asset inventory and vulnerability management processes should be updated to reflect this vulnerability and track exceptions and retest remediated assets.
Technical summary
The Incus system container and virtual machine manager has a vulnerability (CVE-2026-62313) where project-level enforcement of restricted.containers.privilege=isolated can be bypassed, allowing creation of non-isolated containers. This issue is addressed in version 7.3.0. The vulnerability allows users to create containers that share the host uid/gid map instead of receiving unique, non-overlapping ranges, weakening the isolation boundary between co-tenant containers and the host.
Defensive priority
Users of Incus system container and virtual machine manager should prioritize updating to version 7.3.0 or later to address the identified vulnerability.
Recommended defensive actions
- Review the official CVE record and NVD details to validate affected scope, severity, and vendor guidance.
- Confirm whether affected Incus deployments exist in managed environments and assign an owner for follow-up.
- Plan vendor-supported updates to version 7.3.0 or later through normal change control where exposure is confirmed.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Monitor container deployments for potential security risks related to CVE-2026-62313.
Evidence notes
The CVE record indicates that Incus versions prior to 7.3.0 are vulnerable to a security issue where project-level enforcement of restricted.containers.privilege=isolated can be bypassed. The NVD entry is currently limited, and further review of the official advisory is necessary to validate affected scope, severity, and vendor guidance. Users should verify their deployments and plan for updates or mitigations through normal change control. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified.
Official resources
-
CVE-2026-62313 CVE record
CVE.org
-
CVE-2026-62313 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T15:16:45.867Z and has not been modified since then.