Privilege Escalation Vulnerability in Incus System Container Manager
CVE-2026-62940
9.9CRITICAL
What is CVE-2026-62940?
Incus, a system container and virtual machine manager, suffers from a vulnerability that allows restricted project users to exploit user-supplied configuration overrides during instance migrations between cluster members. This occurs when critical security keys such as security.privileged and raw.lxc are applied without enforcing project restrictions, enabling a potential breach that can escalate privileges to a privileged container and facilitate escape to the host system. The vulnerability has been addressed in version 7.3.0.
Affected Version(s)
incus < 7.3.0
