Privilege Escalation Vulnerability in Incus System Container Manager
CVE-2026-62940

9.9CRITICAL

Key Information:

Vendor

Lxc

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-62940?

Incus, a system container and virtual machine manager, suffers from a vulnerability that allows restricted project users to exploit user-supplied configuration overrides during instance migrations between cluster members. This occurs when critical security keys such as security.privileged and raw.lxc are applied without enforcing project restrictions, enabling a potential breach that can escalate privileges to a privileged container and facilitate escape to the host system. The vulnerability has been addressed in version 7.3.0.

Affected Version(s)

incus < 7.3.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.