Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-48753: Incus S3 upload can write files anywhere

CVE-2026-48753 · published 13 days ago
Summary

Incus's S3-compatible upload feature lets attackers trick the system into creating files in any location by using specially crafted path names. This could let a malicious user place scripts that run automatically, potentially taking control of the server. Apply the latest Incus update or restrict S3 upload access until the fix is deployed.

What to do
  • Update debian incus to version 7.0.0-2.
  • Update github.com lxc to version 7.1.0.
  • Update lxc github.com/lxc/incus/v7 to version 7.1.0.
Affected software
Ecosystem VendorProductAffected versions
Debian:14 debian incus < 7.0.0-2
Fix: upgrade to 7.0.0-2
go github.com lxc < 7.1.0
Fix: upgrade to 7.1.0
Go lxc github.com/lxc/incus All versions
Go lxc github.com/lxc/incus/v6 All versions
Go lxc github.com/lxc/incus/v7 < 7.1.0
Fix: upgrade to 7.1.0
– lxc incus < 7.1.0
Ubuntu:Pro:24.04:LTS canonical incus All versions
Ubuntu:25.10 canonical incus All versions
Ubuntu:Pro:26.04:LTS canonical incus All versions
Original advisory text
Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. ...
Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue.
Severity
9.9 Critical
CVSS 3.1: 9.9 (GHSA)
CVSS 3.1: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-73External Control of File Name or Path
Timeline
Published21 Aug 2026
Updated3 Sep 2026
First seen7 Jun 2026
Monitor software like this
Free during beta