[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-62941":6},{"stargazers_count":4,"fetched_at":5},7,"2026-08-21T09:42:53.246Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":20,"aliases":21,"duplicate_of":9,"upstream":24,"downstream":25,"duplicates":26,"related":27,"reserved_at":9,"published_at":28,"modified_at":28,"state":29,"summary":30,"references_raw":37,"kevs":63,"epss":9,"epss_history":64,"metrics":65,"affected":71},"CVE-2026-62941","Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the source instance's configuration is merged into the request. Dangerous configuration keys (including `security.privileged`, `raw.lxc`, `raw.apparmor`) from the source instance are merged AFTER the check passes, bypassing all project restrictions on the target project. Version 7.3.0 patches the issue.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-863","Incorrect Authorization","The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.","weakness","Incomplete","Class","High",[],[],[22,23],"UBUNTU-CVE-2026-62941","DEBIAN-CVE-2026-62941",[],[],[],[],"2026-08-21T14:47:56.724Z","PUBLISHED",{"cisa_kev":31,"cisa_ransomware":31,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":32,"severity_score":33,"severity_version":34,"severity_source":35,"severity_vector":36,"severity_status":29},false,"critical",9.9,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",[38,44,48,53,57],{"url":39,"sources":40,"tags":42},"https://ubuntu.com/security/CVE-2026-62941",[41],"osv_ubuntu",[43],"REPORT",{"url":45,"sources":46,"tags":47},"https://www.cve.org/CVERecord?id=CVE-2026-62941",[41],[43],{"url":49,"sources":50,"tags":51},"https://github.com/lxc/incus/security/advisories/GHSA-mq9x-prm8-3vpw",[41,35],[43,52],"X Refsource CONFIRM",{"url":54,"sources":55,"tags":56},"https://github.com/lxc/incus/pull/3750",[41],[43],{"url":58,"sources":59,"tags":61},"https://security-tracker.debian.org/tracker/CVE-2026-62941",[60],"osv_debian",[62],"Advisory",[],[],[66],{"source":35,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":67,"cvss_v4_0":9},{"baseScore":33,"baseSeverity":68,"vectorString":36,"impactScore":69,"exploitabilityScore":70},"CRITICAL",10,7.9,[72,87,93],{"ecosystem":73,"name":74,"vendor":75,"product":74,"cpe_part":9,"purl_type":76,"purl_namespace":75,"purl_name":74,"source":9,"versions":77},"Debian","incus","debian","deb",[78,84],{"version":79,"is_range":80,"range_type":81,"version_start":9,"version_start_type":9,"version_end":82,"version_end_type":83,"fixed_in":9},"lt6_0_4_2+deb13u9",true,"ecosystem","6.0.4-2+deb13u9","excluding",{"version":85,"is_range":80,"range_type":81,"version_start":9,"version_start_type":9,"version_end":86,"version_end_type":83,"fixed_in":9},"lt7_0_1_2","7.0.1-2",{"ecosystem":88,"name":74,"vendor":89,"product":74,"cpe_part":9,"purl_type":76,"purl_namespace":89,"purl_name":74,"source":9,"versions":90},"Ubuntu","ubuntu",[91],{"version":92,"is_range":80,"range_type":81,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"all",{"ecosystem":9,"name":74,"vendor":94,"product":74,"cpe_part":95,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":96},"lxc","a",[97],{"version":98,"is_range":80,"range_type":35,"version_start":9,"version_start_type":9,"version_end":99,"version_end_type":83,"fixed_in":9},"\u003C 7.3.0","7.3.0"]