PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-62867 lxc CVE debrief

CVE-2026-62867 is a critical vulnerability in Incus, a system container and virtual machine manager. The vulnerability allows project-scoped users to inject arbitrary arguments into filesystem creation commands executed as root, potentially leading to privilege escalation and unauthorized access. This issue arises from improper validation of user-provided block.create_options in storage volume configuration. Affected deployments should verify exposure, assess potential impact, and prioritize remediation. The CVE record was published on 2026-08-21T15:16:46.003Z and has not been modified since then.

Vendor
lxc
Product
incus
CVSS
CRITICAL 9.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-09-18
Advisory published
2026-08-21
Advisory updated
2026-09-18

Who should care

Defenders managing Incus deployments, particularly those with project-scoped user access, should assess exposure and verify if their configurations are vulnerable to argument injection attacks.

Why it matters

CVE-2026-62867 allows project-scoped users in Incus to inject arbitrary arguments into filesystem creation commands executed as root, potentially leading to privilege escalation and unauthorized access. Defenders should verify exposure, assess potential impact, and prioritize remediation.

  • Potential for arbitrary argument injection into filesystem creation commands executed as root.
  • Possible elevation of privileges for project-scoped users.
  • Risk of unauthorized access to sensitive data or systems.
  • Need for verification of Incus version and configuration to ensure remediation.

Technical summary

The Incus system container and virtual machine manager is vulnerable to argument injection due to improper validation of user-provided block.create_options in storage volume configuration. This allows project-scoped users to inject arbitrary arguments into filesystem creation commands executed as root, potentially leading to privilege escalation and unauthorized access. The vulnerability affects Incus versions prior to 7.3.0. Defenders should verify exposure, assess potential impact, and prioritize remediation, focusing on project-scoped user access and storage volume configurations.

Defensive priority

Defenders should prioritize verifying exposure and assessing potential impact, focusing on project-scoped user access and storage volume configurations.

Recommended defensive actions

  • Verify Incus version and assess exposure by checking current version against 7.3.0 or later.
  • Review project-scoped user access and storage volume configurations for potential vulnerabilities.
  • Implement compensating controls, such as restricting user access to storage volume configuration.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in Incus, a system container and virtual machine manager, related to improper validation of user-provided block.create_options in storage volume configuration, leading to argument injection.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-62867 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-62867

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-62867 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-62867

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.