PatchSiren cyber security CVE debrief
CVE-2026-62867 lxc CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T15:16:46.003Z and has not been modified since then. CVE-2026-62867 is a critical vulnerability in Incus, a system container and virtual machine manager. The vulnerability is caused by improper validation of user-provided block.create_options in storage volume configuration, leading to argument injection in the constructed filesystem creation command line. This allows a project-scoped user to inject arbitrary arguments into the binary executed as root. The vulnerability has a CVSS score of 9.9 and is considered critical. Affected Incus deployments should be identified and patched to version 7.3.0 or later. System administrators and security teams responsible for Incus environments should be aware of this vulnerability and take immediate action to patch or mitigate. Project-scoped users with access to storage volume configuration are at risk of exploiting this vulnerability. Additionally, security teams should review Incus project documentation and security advisories to understand potential impact and verify vendor guidance. Vulnerability management and incident response teams should also be notified to prepare for potential exploitation attempts.
- Vendor
- lxc
- Product
- incus
- CVSS
- CRITICAL 9.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-08-21
Who should care
System administrators and security teams responsible for Incus environments should be aware of this vulnerability and take immediate action to patch or mitigate. Project-scoped users with access to storage volume configuration are at risk of exploiting this vulnerability. Additionally, security teams should review Incus project documentation and security advisories to understand potential impact and verify vendor guidance. Vulnerability management and incident response teams should also be notified to prepare for potential exploitation attempts.
Technical summary
CVE-2026-62867 is a critical vulnerability in Incus, a system container and virtual machine manager. The vulnerability is caused by improper validation of user-provided block.create_options in storage volume configuration, leading to argument injection in the constructed filesystem creation command line. This allows a project-scoped user to inject arbitrary arguments into the binary executed as root. The vulnerability has a CVSS score of 9.9 and is considered critical. Affected Incus deployments should be identified and patched to version 7.3.0 or later.
Defensive priority
High priority due to critical severity and potential for arbitrary argument injection as root.
Recommended defensive actions
- Verify Incus version is 7.3.0 or later
- Restrict access to storage volume configuration
- Monitor for suspicious activity in Incus environment
- Implement compensating controls for argument injection
- Review and update incident response plan
Evidence notes
Evidence from official CVE and NVD sources indicates improper validation of user-provided block.create_options in Incus storage volume configuration, leading to argument injection. Limited details available on affected scope and vendor remediation efforts. Further review of Incus project documentation and security advisories is recommended to understand potential impact and verify vendor guidance.
Official resources
-
CVE-2026-62867 CVE record
CVE.org
-
CVE-2026-62867 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T15:16:46.003Z and has not been modified since then.