<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 22:16:38 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-15000</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-15000</link>
      <description>bdu:2026-15000</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-15000</guid>
    </item>
    <item>
      <title>EUVD-2026-357364</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-357364</link>
      <description>EUVD-2026-357364</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-357364</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55622</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55622</link>
      <description>&lt;p&gt;Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don&amp;#39;t have access to and the name of an instance in that project can copy the instance to a new project. This issue could allow an attacker to access secrets in instances they are not authorized to access. Version 7.2.0 patches the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don&amp;#39;t have access to and the name of an instance in that project can copy the instance to a new project. This issue could allow an attacker to access secrets in instances they are not authorized to access. Version 7.2.0 patches the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55622</guid>
    </item>
    <item>
      <title>GHSA-c9f5-j9c3-mhrg — Incus has a project restriction bypass in instance copy across projects</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c9f5-j9c3-mhrg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/lxc/incus/v7/cmd/incusd&lt;/p&gt;
&lt;p&gt;### Summary
Missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don&amp;#39;t have access to and the name of an instance in that project can copy the instance to a new project. This issue could allow an attacker to access secrets in instances they are not authorized to access.&lt;/p&gt;
&lt;p&gt;### Details
`cmd/incusd/instances.go` authorizes `POST /1.0/instances` against the target project. In the copy path, `cmd/incusd/instances_post.go` then loads the source instance from `req.Source.Project` without checking whether the caller can view that source instance.&lt;/p&gt;
&lt;p&gt;The copy must occur on the same server. However, once the copy has been done, nothing prevents a malicious actor from moving the instance to another server.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;#### Setup&lt;/p&gt;
&lt;p&gt;Assumes the target server is remotely accessible and a user/certificate has been added.&lt;/p&gt;
&lt;p&gt;```
# create a new project and instance
incus project create secrets
incus profile show default | incus --project secrets edit default
incus --project secrets init images:debian/trixie secret&lt;/p&gt;
&lt;p&gt;# restrict an existing certificate to prevent access to the project
incus config trust edit cert-fp
#&amp;gt; set, for example
restricted: true
projects:
  - default&lt;/p&gt;
&lt;p&gt;# verification, with the restricted certificate
incus ls remote:
```&lt;/p&gt;
&lt;p&gt;#### Exploitation&lt;/p&gt;
&lt;p&gt;The below script was partly generated. To copy the `secret` instance to the `default` project, the following command can be used.&lt;/p&gt;
&lt;p&gt;```
python3 poc.py --url https://IP-REMOTE:8443 \…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/lxc/incus/v7/cmd/incusd&lt;/p&gt;
&lt;p&gt;### Summary
Missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don&amp;#39;t have access to and the name of an instance in that project can copy the instance to a new project. This issue could allow an attacker to access secrets in instances they are not authorized to access.&lt;/p&gt;
&lt;p&gt;### Details
`cmd/incusd/instances.go` authorizes `POST /1.0/instances` against the target project. In the copy path, `cmd/incusd/instances_post.go` then loads the source instance from `req.Source.Project` without checking whether the caller can view that source instance.&lt;/p&gt;
&lt;p&gt;The copy must occur on the same server. However, once the copy has been done, nothing prevents a malicious actor from moving the instance to another server.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;#### Setup&lt;/p&gt;
&lt;p&gt;Assumes the target server is remotely accessible and a user/certificate has been added.&lt;/p&gt;
&lt;p&gt;```
# create a new project and instance
incus project create secrets
incus profile show default | incus --project secrets edit default
incus --project secrets init images:debian/trixie secret&lt;/p&gt;
&lt;p&gt;# restrict an existing certificate to prevent access to the project
incus config trust edit cert-fp
#&amp;gt; set, for example
restricted: true
projects:
  - default&lt;/p&gt;
&lt;p&gt;# verification, with the restricted certificate
incus ls remote:
```&lt;/p&gt;
&lt;p&gt;#### Exploitation&lt;/p&gt;
&lt;p&gt;The below script was partly generated. To copy the `secret` instance to the `default` project, the following command can be used.&lt;/p&gt;
&lt;p&gt;```
python3 poc.py --url https://IP-REMOTE:8443 \…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c9f5-j9c3-mhrg</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11651-1 — incus-7.4-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11651-1</link>
      <description>&lt;p&gt;incus-7.4-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;incus-7.4-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11651-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-55622</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-55622</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: lxd, Ubuntu:Pro:18.04:LTS: lxd, Ubuntu:20.04:LTS: lxd, Ubuntu:Pro:24.04:LTS: incus, Ubuntu:25.10: incus, Ubuntu:Pro:26.04:LTS: incus&lt;/p&gt;
&lt;p&gt;Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don&amp;#39;t have access to and the name of an instance in that project can copy the instance to a new project. This issue could allow an attacker to access secrets in instances they are not authorized to access. Version 7.2.0 patches the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: lxd, Ubuntu:Pro:18.04:LTS: lxd, Ubuntu:20.04:LTS: lxd, Ubuntu:Pro:24.04:LTS: incus, Ubuntu:25.10: incus, Ubuntu:Pro:26.04:LTS: incus&lt;/p&gt;
&lt;p&gt;Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don&amp;#39;t have access to and the name of an instance in that project can copy the instance to a new project. This issue could allow an attacker to access secrets in instances they are not authorized to access. Version 7.2.0 patches the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-55622</guid>
    </item>
  </channel>
</rss>
