CVE-2026-33898 affects Incus prior to version 6.23.0. The vulnerability is in the temporary local web server spawned by the incus webui command. incus webui starts a web server bound to a random localhost port and provides the user with a URL containing an authentication token. After successful use of that token, Incus sets a cookie so subsequent requests do not need to carry the token in the URL. While the cookie value is correctly validated, the server does not correctly validate the authentication token when it is supplied in the URL, and an invalid token may be accepted. This is an improper authentication flaw that can allow unauthorized access to the Incus web UI with the privileges of the user who launched incus webui.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
incus webui. This can enable unauthorized access to the user's Incus instances and potentially associated system resources. In a local multi-user environment, this may result in privilege escalation to the affected user's Incus management context. In a remote attack scenario, if an attacker can induce the local user to interact with the temporary web UI server, the attacker may obtain unauthorized control over Incus operations, with high impact to confidentiality, integrity, and availability.If you can’t patch tonight, do this now.
incus webui on untrusted systems or in multi-user environments, and limit opportunities for other local users or untrusted remote content to interact with the temporary localhost web server. Only launch the web UI when necessary and close it promptly after use. Reducing exposure to local attackers and avoiding user interaction with untrusted content can lower exploitation risk, but the definitive fix is upgrading to 6.23.0 or later.Patch, then assume compromise.
incus webui web server.No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.