PT-2026-75899 · Incus · Incus

CVE-2026-62867

·

Published

2026-07-31

·

Updated

2026-09-05

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Incus versions prior to 7.3.0
Description Improper validation of the block.create options variable in storage volume configuration allows a project-scoped user to perform argument injection. This occurs during the construction of the filesystem creation command line, enabling the injection of arbitrary arguments into a binary executed with root privileges.
Recommendations Update to version 7.3.0.

Exploit

Fix

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62867
GHSA-Q7XW-R4W2-2WCM
OPENSUSE-SU-2026:11651-1

Affected Products

Incus