These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (including security-critical keys like `security.privileged` and `raw.lxc`) are applied without any project restriction enforcement, allowing a restricted project user to escalate to a privileged container and escape to the host. Versi [truncated]
CVE-2026-62867 is a critical vulnerability in Incus, a system container and virtual machine manager. The vulnerability allows project-scoped users to inject arbitrary arguments into filesystem creation commands executed as root, potentially leading to privilege escalation and unauthorized access. This issue arises from improper validation of user-provided block.create_options in storage volume configurati [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T15:16:45.867Z and has not been modified since then. Incus is a system container and virtual machine manager. Prior to version 7.3.0, project-level enforcement of restricted.containers.privilege=isolated can be trivially bypassed, allowing a user to create a non-isolated (shared host idmap) contai [truncated]
Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in that project can copy the instance to a new project. This issue could allow an attacker to access secrets in instances they are not authorized to access.
CVE-2026-48769 is a critical vulnerability in Incus, a system container and virtual machine manager. A malicious image server can exploit an arbitrary file write issue in the Incus client by returning a crafted 'Incus-Image-Hash' header, potentially leading to arbitrary command execution as root on the server. The issue was patched in version 7.2.0.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T15:16:41.210Z and has not been modified since then. This vulnerability affects Incus, a system container and virtual machine manager, where an authenticated user with can_create_storage_volumes permission can crash the incusd daemon by uploading a backup tarball with a missing volume_snapshots[*] [truncated]
CVE-2026-48755 is a critical vulnerability in Incus, a system container and virtual machine manager. The vulnerability is caused by improper validation of user-provided backup compression algorithm, leading to argument injection in the constructed command line. This allows for arbitrary file writes on the host and potentially leads to arbitrary command execution. The issue was patched in version 7.1.0.
Incus system container and virtual machine manager versions prior to 7.1.0 are vulnerable to path traversal via the S3 protocol upload endpoint, allowing creation of arbitrary files on the host, which could lead to arbitrary command execution. The issue is fixed in version 7.1.0. This vulnerability has a high impact on system administrators and security teams, as it can lead to potential command execution [truncated]
The CVE-2026-48750 record indicates a critical vulnerability in Incus, a system container and virtual machine manager. The vulnerability exists in the `record-output` parameter of the `/instances/$name/exec` endpoint, which stores command output in the `exec-output` directory of the instance. If `exec-output` is a symlink, files can be written to an arbitrary location, allowing for arbitrary content in th [truncated]
A specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution in Incus prior to version 7.2.0. This issue requires immediate attention from system administrators and security teams managing Incus installations, especially those with exposure to untrusted image sources. The vulnerability allows for potential arbitrary command exec [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T15:16:40.067Z and has not been modified since then. A nil-pointer dereference in Incus versions prior to 7.1.0 allows authenticated users with instance creation permissions to trigger a denial-of-service condition. This issue is a sibling of GHSA-fwj8-62r8-8p8m, GHSA-r7w7-mmxr-47r9, and GHSA-x5r6 [truncated]