CVE-2026-55622
7.7LXC · Incus
LXC Incus versions prior to 7.2.0 are vulnerable to an improper access control issue, potentially allowing authenticated users to manipulate the system environment.
Executive summary
A high-severity access control vulnerability in LXC Incus, for which a proof-of-concept exists, allows authenticated users to bypass security restrictions.
Vulnerability
This vulnerability involves improper access control (CWE-284) within the Incus management framework. It allows an authenticated user with low-level privileges (PR:L) to perform unauthorized operations, potentially impacting the confidentiality and integrity of containerized workloads.
Business impact
The ability for an authenticated user to bypass access controls can lead to unauthorized modification of container settings or exposure of sensitive environment data. Given the CVSS score of 7.7, this vulnerability poses a high risk to the overall stability and security of the virtualized infrastructure.
Remediation
Immediate Action: Apply the vendor-supplied security update by upgrading Incus to version 7.2.0 or later.
Proactive Monitoring: Monitor system logs for unusual container deployment or configuration changes that deviate from established operational baselines.
Compensating Controls: Enforce the principle of least privilege for all users who interact with the Incus management interface and limit access to the network management port.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the existence of a proof-of-concept, the urgency to patch this vulnerability is elevated. Organizations should prioritize updating to version 7.2.0 to mitigate the risk of unauthorized access and potential system compromise.