CVE-2026-48753
Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.9
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.71%
- CWE
- CWE-73
- Published
- 2026-08-21
- Last modified
- 2026-08-21
Affected products
- lxc incus
Weakness type
Related vulnerabilities
- CVE-2026-50148 — Metabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Write
- CVE-2026-20358 — Cisco Crosswork Security Hardening Release: August 2026
- CVE-2026-11526 — GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle
- CVE-2026-67429 — Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
- CVE-2025-71338 — Flowise - Arbitrary File Write to Remote Code Execution via document-store API
- CVE-2026-48750 — Incus has an arbitrary file write on host via `exec-output` symlink in crafted image
- CVE-2026-9559 — A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files dur
- CVE-2026-63343 — Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root