# CVE-2026-48753

## Summary

- **CVE ID:** CVE-2026-48753
- **Severity:** CRITICAL
- **CVSS Score:** 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-73
- **Published:** Aug 21, 2026
- **Last Modified:** Aug 21, 2026

## Description

Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue.

## Affected Products

- lxc — incus (< 7.1.0)

## References

- [CNA](https://github.com/lxc/incus/security/advisories/GHSA-ccjc-4qc3-jxqc)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.71%
- **EPSS Percentile:** 51.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._