PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-62867 lxc CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T15:16:46.003Z and has not been modified since then. CVE-2026-62867 is a critical vulnerability in Incus, a system container and virtual machine manager. The vulnerability is caused by improper validation of user-provided block.create_options in storage volume configuration, leading to argument injection in the constructed filesystem creation command line. This allows a project-scoped user to inject arbitrary arguments into the binary executed as root. The vulnerability has a CVSS score of 9.9 and is considered critical. Affected Incus deployments should be identified and patched to version 7.3.0 or later. System administrators and security teams responsible for Incus environments should be aware of this vulnerability and take immediate action to patch or mitigate. Project-scoped users with access to storage volume configuration are at risk of exploiting this vulnerability. Additionally, security teams should review Incus project documentation and security advisories to understand potential impact and verify vendor guidance. Vulnerability management and incident response teams should also be notified to prepare for potential exploitation attempts.

Vendor
lxc
Product
incus
CVSS
CRITICAL 9.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-08-21
Advisory published
2026-08-21
Advisory updated
2026-08-21

Who should care

System administrators and security teams responsible for Incus environments should be aware of this vulnerability and take immediate action to patch or mitigate. Project-scoped users with access to storage volume configuration are at risk of exploiting this vulnerability. Additionally, security teams should review Incus project documentation and security advisories to understand potential impact and verify vendor guidance. Vulnerability management and incident response teams should also be notified to prepare for potential exploitation attempts.

Technical summary

CVE-2026-62867 is a critical vulnerability in Incus, a system container and virtual machine manager. The vulnerability is caused by improper validation of user-provided block.create_options in storage volume configuration, leading to argument injection in the constructed filesystem creation command line. This allows a project-scoped user to inject arbitrary arguments into the binary executed as root. The vulnerability has a CVSS score of 9.9 and is considered critical. Affected Incus deployments should be identified and patched to version 7.3.0 or later.

Defensive priority

High priority due to critical severity and potential for arbitrary argument injection as root.

Recommended defensive actions

  • Verify Incus version is 7.3.0 or later
  • Restrict access to storage volume configuration
  • Monitor for suspicious activity in Incus environment
  • Implement compensating controls for argument injection
  • Review and update incident response plan

Evidence notes

Evidence from official CVE and NVD sources indicates improper validation of user-provided block.create_options in Incus storage volume configuration, leading to argument injection. Limited details available on affected scope and vendor remediation efforts. Further review of Incus project documentation and security advisories is recommended to understand potential impact and verify vendor guidance.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T15:16:46.003Z and has not been modified since then.