CVE-2026-33898Disclosure(linuxcontainers / incus)

LOWCVSS 8.8 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch linuxcontainers incus systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the authentication token such that an invalid value will be accepted. `incus webui` runs a local web server on a random localhost port. For authentication, it provides the user with a URL containing an authentication token. When accessed with that token, Incus creates a cookie persisting that token without needing to include it in subsequent HTTP requests. While the Incus client correctly validates the value of the cookie, it does not correctly validate the token when passed int the URL. This allows for an attacker able to locate and talk to the temporary web server on localhost to have as much access to Incus as the user who ran `incus webui`. This can lead to privilege escalation by another local user or an access to the user's Incus instances and possibly system resources by a remote attack able to trick the local user into interacting with the Incus UI web server. Version 6.23.0 patches the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • incus

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Products
incus

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-27: 4Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-27: 303-27
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVE@CVEnew
    General

    CVE-2026-33898 Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the authentication tok… https://www.cve.org/CVERecord?id=CVE-2026-33898

    Post summary

    The post notes CVE-2026-33898 affecting Incus before version 6.23.0 with a token validation issue, but provides no PoC, exploit details, patch, or evidence of active attacks.

    00000121
    56.9K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-33898 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33898 #CVE-2026-33898 #CVE #High #CyberSecurity #InfoSec https://t.co/jD3erljoVQ

    Post summary

    The tweet announces CVE-2026-33898 with a severity score of 8.8 and high risk, but provides only minimal details beyond the NVD reference.

    0000035
    123 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-33898 - High Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the authentication token such that an invalid v... https://www.thehackerwire.com/vulnerability/CVE-2026-33898/ https://t.co/IXOGki50up

    Post summary

    CVE‑2026‑33898 is a high‑severity flaw in Incus before v6.23.0 where the web UI’s authentication token validation is incorrect, potentially allowing unauthorized access.

    0000050
    163 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33898: HIGH] Vulnerability in Incus web server authentication before version 6.23.0 allowed for privilege escalation & remote attacks. Update to version 6.23.0 to fix the issue.#cve,CVE-2026-33898,#cybersecurity https://cvefind.com/CVE-2026-33898

    Post summary

    The advisory describes a privilege escalation flaw in Incus web server authentication and recommends updating to version 6.23.0; no proof of concept, exploit, or active exploitation details are provided.

    0000056
    617 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxcontainersincus---

Explore more