Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-48752: Incus lets attackers read and change host files

CVE-2026-48752 · published 13 days ago
Summary

Incus can be tricked with a specially crafted container image or backup to follow a hidden link that points to any folder on the server. This lets an attacker view or overwrite files on the host, potentially planting malicious scripts. Use the latest Incus release that removes the unsafe link handling, or apply the vendor's patch and avoid loading untrusted images.

What to do
  • Update github.com lxc to version 7.2.0.
  • Update lxc github.com/lxc/incus/v7 to version 7.2.0.
  • Update debian incus to version 6.0.4-2+deb13u8.
  • Update debian incus to version 7.0.0-5.
  • Update debian lxd to version 5.0.2+git20231211.1364ae4-9+deb13u7.
Affected software
Ecosystem VendorProductAffected versions
Ubuntu:Pro:16.04:LTS canonical lxd All versions
Debian:13 debian incus < 6.0.4-2+deb13u8
Fix: upgrade to 6.0.4-2+deb13u8
Debian:14 debian incus < 7.0.0-5
Fix: upgrade to 7.0.0-5
Debian:12 debian lxd All versions
Debian:13 debian lxd < 5.0.2+git20231211.1364ae4-9+deb13u7
Fix: upgrade to 5.0.2+git20231211.1364ae4-9+deb13u7
go github.com lxc < 7.2.0
Fix: upgrade to 7.2.0
Go lxc github.com/lxc/incus All versions
Go lxc github.com/lxc/incus/v6 All versions
Go lxc github.com/lxc/incus/v7 < 7.2.0
Fix: upgrade to 7.2.0
– lxc incus < 7.2.0
Ubuntu:Pro:18.04:LTS canonical lxd All versions
Ubuntu:20.04:LTS canonical lxd All versions
Ubuntu:Pro:24.04:LTS canonical incus All versions
Ubuntu:25.10 canonical incus All versions
Ubuntu:Pro:26.04:LTS canonical incus All versions
Original advisory text
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possib...
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 patches the issue.
Severity
9.9 Critical
CVSS 3.1: 9.9 (GHSA)
CVSS 3.1: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-73External Control of File Name or Path
Timeline
Published21 Aug 2026
Updated2 Sep 2026
First seen26 Jun 2026
Monitor software like this
Free during beta