PatchSiren cyber security CVE debrief
CVE-2026-92761 retspen CVE debrief
WebVirtCloud has a high-severity vulnerability allowing view-only users to perform privileged actions due to improper validation of permission flags in UserInstance grants. This issue enables attackers with read-only grants to power off virtual machines, reset root passwords, install SSH keys, and manage ISO images by exploiting the get_instance gate. The vulnerability arises from the improper validation of permission flags in UserInstance grants, allowing users with read-only access to perform sensitive actions. Defenders managing virtual machine infrastructure using WebVirtCloud should assess their exposure to this vulnerability and prioritize remediation efforts to prevent the 7
- Vendor
- retspen
- Product
- webvirtcloud
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-16
- Original CVE updated
- 2026-09-21
- Advisory published
- 2026-09-16
- Advisory updated
- 2026-09-21
Who should care
Defenders managing virtual machine infrastructure using WebVirtCloud should assess their exposure to this vulnerability. Specifically, roles such as system administrators, cloud administrators, and security teams responsible for virtualization environments should verify if their configurations are vulnerable and prioritize remediation efforts.
Why it matters
CVE-2026-92761 is a high-severity vulnerability in WebVirtCloud that allows view-only users to perform privileged actions. Defenders managing virtual machine infrastructure using WebVirtCloud should assess their exposure and prioritize remediation efforts to prevent exploitation.
- View-only users can perform privileged actions, potentially leading to unauthorized changes in the virtual machine environment.
- Attackers can exploit this vulnerability to gain elevated control over virtual machines, allowing for actions such as powering off VMs, resetting root passwords, and installing SSH keys.
- Defenders need to verify if their WebVirtCloud instances are vulnerable and prioritize remediation to prevent exploitation.
- Remediation efforts should focus on updating or patching WebVirtCloud to properly validate permission flags and restrict access to sensitive actions for view-only users.
Technical summary
The vulnerability in WebVirtCloud arises from the improper validation of permission flags in UserInstance grants. This allows users with read-only access to perform actions such as powering off virtual machines, resetting root passwords, installing SSH keys, and managing ISO images. The issue is related to the get_instance gate, which only checks for the existence of a grant without properly validating the permission flags.
Defensive priority
Defenders should prioritize verifying and remediating this vulnerability, especially in environments where WebVirtCloud is used to manage virtual machines.
Recommended defensive actions
- Verify WebVirtCloud instance configurations to ensure proper validation of permission flags.
- Restrict access to sensitive actions for view-only users.
- Monitor for exploitation attempts targeting this vulnerability.
- Apply patches or updates once available from the vendor.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide details about the vulnerability, including its description and CVSS score. However, the exact versions of WebVirtCloud affected and the specific remediation steps are not provided in the corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-92761 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-92761
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-92761 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92761
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/retspen/webvirtcloud
-
Source reference
Unverified legacy reference
URL: https://github.com/retspen/webvirtcloud/blob/1b2da68b2800f94674dd96f4a986cde30ac88280/instances/views.py
-
Source reference
Unverified legacy reference
URL: https://github.com/retspen/webvirtcloud/issues/682
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/webvirtcloud-missing-authorization-on-instance-control-actions
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.