{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/incus-v7--7.2.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:lxc:incus:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.7,"id":"CVE-2026-55621"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Incus (v7 \u003c 7.2.0)","Incus (v6 \u003c= 6.23.0)","Incus (\u003c= 0.7.0)"],"_cs_severities":["high"],"_cs_tags":["authorization-bypass","cve-2026-55621"],"_cs_type":"advisory","_cs_vendors":["LXC"],"content_html":"\u003cp\u003eThe Incus storage volume creation handler is susceptible to an authorization bypass vulnerability identified as CVE-2026-55621. This flaw allows an authenticated but restricted user to copy custom storage volumes from projects they are not authorized to access into a project under their control. The issue arises because the system verifies authorization for the target project but fails to perform an entitlement check, such as a 'CanView' verification, on the source volume or project before passing the user-controlled source parameter to the copy function. An attacker only requires knowledge of the target project name and the specific custom volume name to trigger the unauthorized copy. While the operation is restricted to the local server, the resulting copy can subsequently be moved to external infrastructure. This vulnerability impacts Incus versions v7 prior to 7.2.0, v6 through 6.23.0, and baseline versions up to 0.7.0.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the Incus API using an existing user certificate with restricted project access.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the name of a target project and a sensitive custom volume residing within that project.\u003c/li\u003e\n\u003cli\u003eAttacker initiates an HTTP POST request to the \u003ccode\u003e/1.0/storage-pools/{pool}/volumes/custom\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eThe request payload includes the attacker-controlled \u003ccode\u003esource.project\u003c/code\u003e and \u003ccode\u003esource.name\u003c/code\u003e fields.\u003c/li\u003e\n\u003cli\u003eThe Incus storage volume creation handler validates the authorization for the destination project.\u003c/li\u003e\n\u003cli\u003eThe handler fails to perform an entitlement or \u003ccode\u003eCanView\u003c/code\u003e check on the source project and volume.\u003c/li\u003e\n\u003cli\u003eThe system creates a copy of the unauthorized custom volume in the attacker-controlled project.\u003c/li\u003e\n\u003cli\u003eAttacker accesses the copied volume to exfiltrate sensitive data or credentials.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthorized access to sensitive data stored in custom volumes. If the volume contains system secrets, database files, or configuration data, the attacker can leverage this information for further lateral movement or privilege escalation within the environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the upgrade of all Incus instances to the patched versions as indicated by the vendor. For v7, upgrade to 7.2.0 or later; for v6, move to a patched release beyond 6.23.0. In the interim, restrict access to the Incus API to known, trusted certificates and perform regular audits of storage volume access logs to identify attempts to copy volumes across projects.\u003c/p\u003e\n","date_modified":"2026-08-28T21:15:04Z","date_published":"2026-08-28T21:15:04Z","id":"https://feed.craftedsignal.io/briefs/2026-08-incus-bypass/","summary":"A vulnerability in Incus allows unauthorized users to bypass project restrictions and copy custom storage volumes by exploiting missing authorization checks in the creation handler.","title":"Incus Custom Volume Authorization Bypass","url":"https://feed.craftedsignal.io/briefs/2026-08-incus-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Incus (V7 \u003c 7.2.0)","version":"https://jsonfeed.org/version/1.1"}