CVE-2026-55621: Incus has a project restriction bypass for custom volume copy across projects
Missing authorization checks exist for custom volume copying where an attacker who knows the name of a project that they don’t have access to and the name of a custom volume in that project can copy the custom volume to a new project. This issue could allow an attacker to access secrets in custom volumes they are not authorized to access.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-55621 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →