Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-48753: Incus S3 upload can write files anywhere
CVE-2026-48753 · published 13 days ago
Summary
Incus's S3-compatible upload feature lets attackers trick the system into creating files in any location by using specially crafted path names. This could let a malicious user place scripts that run automatically, potentially taking control of the server. Apply the latest Incus update or restrict S3 upload access until the fix is deployed.
What to do
- Update debian incus to version 7.0.0-2.
- Update github.com lxc to version 7.1.0.
- Update lxc github.com/lxc/incus/v7 to version 7.1.0.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:14 | debian | incus |
< 7.0.0-2 Fix: upgrade to 7.0.0-2
|
| go | github.com | lxc |
< 7.1.0 Fix: upgrade to 7.1.0
|
| Go | lxc | github.com/lxc/incus | All versions |
| Go | lxc | github.com/lxc/incus/v6 | All versions |
| Go | lxc | github.com/lxc/incus/v7 |
< 7.1.0 Fix: upgrade to 7.1.0
|
| – | lxc | incus | < 7.1.0 |
| Ubuntu:Pro:24.04:LTS | canonical | incus | All versions |
| Ubuntu:25.10 | canonical | incus | All versions |
| Ubuntu:Pro:26.04:LTS | canonical | incus | All versions |
Original advisory text
Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. ...
Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue.
References
- https://github.com/advisories/GHSA-ccjc-4qc3-jxqc
- https://security-tracker.debian.org/tracker/CVE-2026-48753 Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-48753 Third Party Advisory
- https://github.com/lxc/incus/security/advisories/GHSA-ccjc-4qc3-jxqc Third Party Advisory
- https://ubuntu.com/security/CVE-2026-48753 Third Party Advisory
- https://github.com/lxc/incus/pull/3425 Third Party Advisory
Severity
9.9
Critical
CVSS 3.1: 9.9 (GHSA)
CVSS 3.1: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-73External Control of File Name or Path
Timeline
Published21 Aug 2026
Updated3 Sep 2026
First seen7 Jun 2026
Sources
DEBIAN-CVE-2026-48753 · OSV
UBUNTU-CVE-2026-48753 · OSV
CVE-2026-48753 · NVD
GHSA-ccjc-4qc3-jxqc · GHSA
GO-2026-5802 · OSV
CVE-2026-48753 · MITRE
Monitor software like this
Free during beta