Bug 2452051 (CVE-2026-33898)
| Summary: | CVE-2026-33898 incus: Incus: Privilege escalation and unauthorized access due to improper authentication token validation in web UI | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Incus, a system container and virtual machine manager. The `incus webui` component incorrectly validates authentication tokens when they are passed in the URL. This vulnerability allows a local attacker, or a remote attacker who can trick a local user into interacting with the Incus UI web server, to gain unauthorized access. Successful exploitation could lead to privilege escalation or unauthorized access to Incus instances and potentially system resources.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2452105 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-03-27 00:01:47 UTC
|