CVE-2026-92761

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
16/09/2026
Last modified:
23/09/2026

Description

WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only users to perform privileged actions. Attackers with read-only grants can power off virtual machines, reset root passwords, install SSH keys, and manage ISO images by exploiting the get_instance gate that only checks grant existence.