Authentication Token Validation Flaw in Incus Web UI by LXC
CVE-2026-33898

8.8HIGH

Key Information:

Vendor

Lxc

Status
Vendor
CVE Published:
26 March 2026

What is CVE-2026-33898?

The Incus system container and virtual machine manager has an improper authentication issue in the web server spawned by incus webui. This flaw allows an invalid authentication token to be accepted, enabling an attacker to potentially gain access as if they were the user who initiated the web server. This vulnerability can be exploited locally or by tricking a user into accessing the compromised web interface, ultimately leading to unauthorized access to Incus instances and potentially broader system resources. The issue is resolved in version 6.23.0.

Affected Version(s)

incus < 6.23.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.