CVE-2026-62940
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (including security-critical keys like security.privileged and raw.lxc) are applied without any project restriction enforcement, allowing a restricted project user to escalate to a privileged container and escape to the host. Version 7.3.0 patches the issue.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62940.json, https://github.com/lxc/incus/security/advisories/GHSA-qw5c-v953-38gw, https://nvd.nist.gov/vuln/detail/CVE-2026-62940