PatchSiren cyber security CVE debrief
CVE-2026-62867 lxc CVE debrief
CVE-2026-62867 is a critical vulnerability in Incus, a system container and virtual machine manager. The vulnerability allows project-scoped users to inject arbitrary arguments into filesystem creation commands executed as root, potentially leading to privilege escalation and unauthorized access. This issue arises from improper validation of user-provided block.create_options in storage volume configuration. Affected deployments should verify exposure, assess potential impact, and prioritize remediation. The CVE record was published on 2026-08-21T15:16:46.003Z and has not been modified since then.
- Vendor
- lxc
- Product
- incus
- CVSS
- CRITICAL 9.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-09-18
Who should care
Defenders managing Incus deployments, particularly those with project-scoped user access, should assess exposure and verify if their configurations are vulnerable to argument injection attacks.
Why it matters
CVE-2026-62867 allows project-scoped users in Incus to inject arbitrary arguments into filesystem creation commands executed as root, potentially leading to privilege escalation and unauthorized access. Defenders should verify exposure, assess potential impact, and prioritize remediation.
- Potential for arbitrary argument injection into filesystem creation commands executed as root.
- Possible elevation of privileges for project-scoped users.
- Risk of unauthorized access to sensitive data or systems.
- Need for verification of Incus version and configuration to ensure remediation.
Technical summary
The Incus system container and virtual machine manager is vulnerable to argument injection due to improper validation of user-provided block.create_options in storage volume configuration. This allows project-scoped users to inject arbitrary arguments into filesystem creation commands executed as root, potentially leading to privilege escalation and unauthorized access. The vulnerability affects Incus versions prior to 7.3.0. Defenders should verify exposure, assess potential impact, and prioritize remediation, focusing on project-scoped user access and storage volume configurations.
Defensive priority
Defenders should prioritize verifying exposure and assessing potential impact, focusing on project-scoped user access and storage volume configurations.
Recommended defensive actions
- Verify Incus version and assess exposure by checking current version against 7.3.0 or later.
- Review project-scoped user access and storage volume configurations for potential vulnerabilities.
- Implement compensating controls, such as restricting user access to storage volume configuration.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in Incus, a system container and virtual machine manager, related to improper validation of user-provided block.create_options in storage volume configuration, leading to argument injection.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-62867 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-62867
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-62867 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-62867
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/lxc/incus/security/advisories/GHSA-q7xw-r4w2-2wcm
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.