Inadequate Container Isolation in Incus by LXC
CVE-2026-62313

4.3MEDIUM

Key Information:

Vendor

Lxc

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-62313?

Incus, a system container and virtual machine manager by LXC, suffers from inadequate enforcement of project-level security settings. Before version 7.3.0, the restriction meant to enforce isolated container deployment can be bypassed with ease. The mechanism fails to properly validate the security.idmap.isolated key, allowing users to create containers without the designated isolation features. This oversight results in multiple containers sharing the host's user ID and group ID mappings, thus compromising the isolation intended between tenants. Such vulnerabilities weaken security postures and could expose systems to potential risks during multi-tenant operation.

Affected Version(s)

incus < 7.3.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.