Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-48751: Incus allows malicious snapshots to bypass project restrictions
GHSA-48q5-w887-33wv
CVE-2026-48751
GO-2026-5799
Summary
Incus has a security issue that allows a malicious user to bypass project restrictions and execute arbitrary commands on the server with root privileges. This is a serious problem because it could allow an attacker to take control of the server. To protect yourself, make sure you're using the latest version of Incus and follow best practices for managing snapshots and projects.
What to do
- Update github.com lxc to version 7.2.0.
- Update lxc github.com/lxc/incus/v7 to version 7.2.0.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| go | github.com | lxc |
< 7.2.0 Fix: upgrade to 7.2.0
|
| Go | lxc | github.com/lxc/incus | All versions |
| Go | lxc | github.com/lxc/incus/v6 | All versions |
| Go | lxc | github.com/lxc/incus/v7 |
< 7.2.0 Fix: upgrade to 7.2.0
|
Original title
Incus has a restricted project bypass leading to arbitrary command execution in github.com/lxc/incus
Original description
Incus has a restricted project bypass leading to arbitrary command execution in github.com/lxc/incus
ghsa CVSS3.1
9.9
Vulnerability type
CWE-862
Missing Authorization
Published: 7 Jul 2026 · Updated: 7 Jul 2026 · First seen: 26 Jun 2026