THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-c9f5-j9c3-mhrg (high) — Incus has a project restriction bypass in instance copy across projects

[GHSA] GHSA-c9f5-j9c3-mhrg (high) — Incus has a project restriction bypass in instance copy across projects

highgithub_advisoriesPublished 2026-08-28

GHSA-c9f5-j9c3-mhrg Severity: high CVE: CVE-2026-55622

Incus has a project restriction bypass in instance copy across projects

### Summary Missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in that project can copy the instance to a new project. This issue could allow an attacker to ac

Indicators of compromise

Original source: https://github.com/advisories/GHSA-c9f5-j9c3-mhrg