Argument Injection Vulnerability in Incus by LXD
CVE-2026-62867
9.9CRITICAL
What is CVE-2026-62867?
Incus, a system container and virtual machine manager developed by LXD, contains a flaw in the validation of user-defined block.create_options during storage volume configuration. This lack of proper validation can result in argument injection, allowing a user with project scope to manipulate the command line of the filesystem creation binary executed with root privileges. The vulnerability is resolved in version 7.3.0 of Incus.
Affected Version(s)
incus < 7.3.0
