PT-2026-75898 · Incus · Incus

CVE-2026-62313

·

Published

2026-07-31

·

Updated

2026-08-31

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Incus versions prior to 7.3.0
Description Project-level enforcement of restricted.containers.privilege=isolated can be bypassed, allowing a user to create a non-isolated container in a project configured to forbid them. The restriction only rejects an explicitly set security.idmap.isolated=false or an empty value, but fails to enforce the restriction when the key is omitted entirely. Since an unset security.idmap.isolated defaults to false, users can obtain a non-isolated container state by omitting the key. This results in containers sharing the host uid/gid map instead of receiving unique, non-overlapping ranges, which weakens the isolation boundary between co-tenant containers and the host.
Recommendations Update to version 7.3.0.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62313
GHSA-53CG-QVG7-M8VG
OPENSUSE-SU-2026:11651-1

Affected Products

Incus