HIGH
retspen
CVE published 2026-09-16
CVE-2026-92761
WebVirtCloud has a high-severity vulnerability allowing view-only users to perform privileged actions due to improper validation of permission flags in UserInstance grants. This issue enables attackers with read-only grants to power off virtual machines, reset root passwords, install SSH keys, and manage ISO images by exploiting the get_instance gate. The vulnerability arises from the improper validation [truncated]