Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-48752: Incus lets attackers read and change host files
CVE-2026-48752 · published 13 days ago
Summary
Incus can be tricked with a specially crafted container image or backup to follow a hidden link that points to any folder on the server. This lets an attacker view or overwrite files on the host, potentially planting malicious scripts. Use the latest Incus release that removes the unsafe link handling, or apply the vendor's patch and avoid loading untrusted images.
What to do
- Update github.com lxc to version 7.2.0.
- Update lxc github.com/lxc/incus/v7 to version 7.2.0.
- Update debian incus to version 6.0.4-2+deb13u8.
- Update debian incus to version 7.0.0-5.
- Update debian lxd to version 5.0.2+git20231211.1364ae4-9+deb13u7.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Ubuntu:Pro:16.04:LTS | canonical | lxd | All versions |
| Debian:13 | debian | incus |
< 6.0.4-2+deb13u8 Fix: upgrade to 6.0.4-2+deb13u8
|
| Debian:14 | debian | incus |
< 7.0.0-5 Fix: upgrade to 7.0.0-5
|
| Debian:12 | debian | lxd | All versions |
| Debian:13 | debian | lxd |
< 5.0.2+git20231211.1364ae4-9+deb13u7 Fix: upgrade to 5.0.2+git20231211.1364ae4-9+deb13u7
|
| go | github.com | lxc |
< 7.2.0 Fix: upgrade to 7.2.0
|
| Go | lxc | github.com/lxc/incus | All versions |
| Go | lxc | github.com/lxc/incus/v6 | All versions |
| Go | lxc | github.com/lxc/incus/v7 |
< 7.2.0 Fix: upgrade to 7.2.0
|
| – | lxc | incus | < 7.2.0 |
| Ubuntu:Pro:18.04:LTS | canonical | lxd | All versions |
| Ubuntu:20.04:LTS | canonical | lxd | All versions |
| Ubuntu:Pro:24.04:LTS | canonical | incus | All versions |
| Ubuntu:25.10 | canonical | incus | All versions |
| Ubuntu:Pro:26.04:LTS | canonical | incus | All versions |
Original advisory text
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possib...
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 patches the issue.
References
- https://security-tracker.debian.org/tracker/CVE-2026-48752 Vendor Advisory
- https://github.com/canonical/lxd/pull/18590 Third Party Advisory
- https://github.com/lxc/incus/commit/cbefa31ae0da8fd96361178aed3a3c631e098fef Third Party Advisory
- https://github.com/lxc/incus/security/advisories/GHSA-vxp5-584q-c479 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-48752 Third Party Advisory
- https://ubuntu.com/security/CVE-2026-48752 Third Party Advisory
- https://github.com/advisories/GHSA-vxp5-584q-c479
Severity
9.9
Critical
CVSS 3.1: 9.9 (GHSA)
CVSS 3.1: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-73External Control of File Name or Path
Timeline
Published21 Aug 2026
Updated2 Sep 2026
First seen26 Jun 2026
Sources
DEBIAN-CVE-2026-48752 · OSV
UBUNTU-CVE-2026-48752 · OSV
GO-2026-5803 · OSV
CVE-2026-48752 · NVD
CVE-2026-48752 · MITRE
GHSA-vxp5-584q-c479 · GHSA
Monitor software like this
Free during beta