CVE-2026-33898
published 2026-03-27CVE-2026-33898: Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the…
PriorityP354high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.35%
26.9th percentile
Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the authentication token such that an invalid value will be accepted. `incus webui` runs a local web server on a random localhost port. For authentication, it provides the user with a URL containing an authentication token. When accessed with that token, Incus creates a cookie persisting that token without needing to include it in subsequent HTTP requests. While the Incus client correctly validates the value of the cookie, it does not correctly validate the token when passed int the URL.
This allows for an attacker able to locate and talk to the temporary web server on localhost to have as much access to Incus as the user who ran `incus webui`. This can lead to privilege escalation by another local user or an access to the user's Incus instances and possibly system resources by a remote attack able to trick the local user into interacting with the Incus UI web server. Version 6.23.0 patches the issue.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | incus | — | — |
| github.com | lxc_incus_v6 | >= 0 < 6.23.0 | 6.23.0 |
| github.com | lxc_incus_v6_cmd_incus | >= 0 < 6.23.0 | 6.23.0 |
| linuxcontainers | incus | < 6.23.0 | 6.23.0 |
| lxc | incus | < 6.23.0 | 6.23.0 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Local Incus UI web server vulnerable to nuthentication bypass in github.com/lxc/incus
osv·2026-04-07
CVE-2026-33898 Local Incus UI web server vulnerable to nuthentication bypass in github.com/lxc/incus
Local Incus UI web server vulnerable to nuthentication bypass in github.com/lxc/incus
Local Incus UI web server vulnerable to nuthentication bypass in github.com/lxc/incus
GHSA
Local Incus UI web server vulnerable to nuthentication bypass
ghsa·2026-03-27
CVE-2026-33898 [HIGH] CWE-287 Local Incus UI web server vulnerable to nuthentication bypass
Local Incus UI web server vulnerable to nuthentication bypass
### Summary
The web server spawned by `incus webui` incorrectly validates the authentication token such that an invalid value will be accepted.
### Details
`incus webui` runs a local web server on a random localhost port. For authentication, it provides the user with a URL containing an authentication token. When accessed with that token, Incus creates a cookie persisting that token without needing to include it in subsequent HTTP requests.
While the Incus client correctly validates the value of the cookie, it does not correctly validate the token when passed int the URL.
This allows for an attacker able to locate and talk to the temporary web server on localhost to have as much access to Incus as the user who ran `incus webu
OSV
Local Incus UI web server vulnerable to nuthentication bypass
osv·2026-03-27
CVE-2026-33898 [HIGH] Local Incus UI web server vulnerable to nuthentication bypass
Local Incus UI web server vulnerable to nuthentication bypass
### Summary
The web server spawned by `incus webui` incorrectly validates the authentication token such that an invalid value will be accepted.
### Details
`incus webui` runs a local web server on a random localhost port. For authentication, it provides the user with a URL containing an authentication token. When accessed with that token, Incus creates a cookie persisting that token without needing to include it in subsequent HTTP requests.
While the Incus client correctly validates the value of the cookie, it does not correctly validate the token when passed int the URL.
This allows for an attacker able to locate and talk to the temporary web server on localhost to have as much access to Incus as the user who ran `incus webu
OSV
CVE-2026-33898: Incus is a system container and virtual machine manager
osv·2026-03-27·CVSS 8.8
CVE-2026-33898 [HIGH] CVE-2026-33898: Incus is a system container and virtual machine manager
Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the authentication token such that an invalid value will be accepted. `incus webui` runs a local web server on a random localhost port. For authentication, it provides the user with a URL containing an authentication token. When accessed with that token, Incus creates a cookie persisting that token without needing to include it in subsequent HTTP requests. While the Incus client correctly validates the value of the cookie, it does not correctly validate the token when passed int the URL. This allows for an attacker able to locate and talk to the temporary web server on localhost to have as much access to Incus as the user who ran `incus webui`. Thi
Red Hat
incus: Incus: Privilege escalation and unauthorized access due to improper authentication token validation in web UI
vendor_redhat·2026-03-26·CVSS 8.8
CVE-2026-33898 [HIGH] CWE-303 incus: Incus: Privilege escalation and unauthorized access due to improper authentication token validation in web UI
incus: Incus: Privilege escalation and unauthorized access due to improper authentication token validation in web UI
Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the authentication token such that an invalid value will be accepted. `incus webui` runs a local web server on a random localhost port. For authentication, it provides the user with a URL containing an authentication token. When accessed with that token, Incus creates a cookie persisting that token without needing to include it in subsequent HTTP requests. While the Incus client correctly validates the value of the cookie, it does not correctly validate the token when passed int the URL.
This allows for an attacker able to locate an
Debian
CVE-2026-33898: incus - Incus is a system container and virtual machine manager. Prior to version 6.23.0...
vendor_debian·2026·CVSS 8.8
CVE-2026-33898 [HIGH] CVE-2026-33898: incus - Incus is a system container and virtual machine manager. Prior to version 6.23.0...
Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the authentication token such that an invalid value will be accepted. `incus webui` runs a local web server on a random localhost port. For authentication, it provides the user with a URL containing an authentication token. When accessed with that token, Incus creates a cookie persisting that token without needing to include it in subsequent HTTP requests. While the Incus client correctly validates the value of the cookie, it does not correctly validate the token when passed int the URL. This allows for an attacker able to locate and talk to the temporary web server on localhost to have as much access to Incus as the user who ran `incus webui`. Thi
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-33898 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-33898 [HIGH] CVE-2026-33898 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33898 :
Homebrew vulnerability analysis and mitigation
incus webui
incus webui
incus webui
Source : NVD
## 8.8
Score
Published March 27, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Homebrew
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 21.4
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
incus
github.com/lxc/incus/v6/cmd/incus
Sources
NVD
Debian 13, 14 Severity LOW No Fix Added at: Mar 29, 2026
Echo Severity HIGH No Fix Added at: Mar 29, 2026
GoLang Severity HIGH Has Fix Added at: Mar 29, 2026
Homebrew Severity HIGH Has Fix Added at: Apr 05, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in you
Bugzilla
CVE-2026-33898 incus: Incus: Privilege escalation and unauthorized access due to improper authentication token validation in web UI [fedora-all]
bugzilla·2026-03-27·CVSS 8.8
CVE-2026-33898 [HIGH] CVE-2026-33898 incus: Incus: Privilege escalation and unauthorized access due to improper authentication token validation in web UI [fedora-all]
CVE-2026-33898 incus: Incus: Privilege escalation and unauthorized access due to improper authentication token validation in web UI [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-a9017d0297 (incus-6.23-1.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-a9017d0297
---
FEDORA-2026-a9017d0297 has been pushed to the Fedora 42 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-a9017d0297`
You can provide feed
2026-03-27
Published