CVE-2026-55621

7.7

LXC · Incus

LXC Incus versions prior to 7.2.0 contain an improper access control vulnerability that may allow authenticated users to perform unauthorized actions.

Executive summary

A high-severity access control vulnerability in LXC Incus allows authenticated users to bypass intended security restrictions, threatening system and container integrity.

Vulnerability

This is an improper access control vulnerability (CWE-284) that allows an authenticated user to perform actions outside their intended scope. The vulnerability requires low privileges (PR:L) and is exploitable over the network (AV:N).

Business impact

Successful exploitation allows for unauthorized interaction with the container management environment, which could lead to resource compromise or unauthorized configuration changes. With a CVSS score of 7.7, this issue presents a significant risk to the security posture of the infrastructure hosting these containers.

Remediation

Immediate Action: Upgrade all instances of LXC Incus to version 7.2.0 or later as directed by the vendor advisory.

Proactive Monitoring: Review audit logs for suspicious container management activity or unauthorized API calls originating from authenticated user sessions.

Compensating Controls: Restrict network access to the Incus management interface to trusted administrative subnets until the software can be patched.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the severity of access control flaws in container management systems, immediate remediation is required. Administrators must update to version 7.2.0 to ensure that standard user privileges are strictly enforced.

More LXC CVEs