Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-48755: Incus backup function can overwrite any file on server

CVE-2026-48755 · published 13 days ago
Summary

Incus lets users pick a program to compress backup data, but it only verifies the first word of the command. Extra options are not checked, so an attacker can add commands that cause the system to write files to any location, potentially allowing them to run their own code. Apply the latest Incus update that corrects this validation, or restrict who can set the backup compression setting.

What to do
  • Update github.com lxc to version 7.2.0.
  • Update lxc github.com/lxc/incus/v7 to version 7.2.0.
  • Update debian incus to version 6.0.4-2+deb13u8.
  • Update debian incus to version 7.0.0-5.
  • Update debian lxd to version 5.0.2+git20231211.1364ae4-9+deb13u7.
Affected software
Ecosystem VendorProductAffected versions
– lxc incus < 7.2.0
Debian:13 debian incus < 6.0.4-2+deb13u8
Fix: upgrade to 6.0.4-2+deb13u8
Debian:14 debian incus < 7.0.0-5
Fix: upgrade to 7.0.0-5
Debian:12 debian lxd All versions
Debian:13 debian lxd < 5.0.2+git20231211.1364ae4-9+deb13u7
Fix: upgrade to 5.0.2+git20231211.1364ae4-9+deb13u7
go github.com lxc < 7.2.0
Fix: upgrade to 7.2.0
Go lxc github.com/lxc/incus All versions
Go lxc github.com/lxc/incus/v6 All versions
Go lxc github.com/lxc/incus/v7 < 7.2.0
Fix: upgrade to 7.2.0
Ubuntu:Pro:16.04:LTS canonical lxd All versions
Ubuntu:Pro:18.04:LTS canonical lxd All versions
Ubuntu:20.04:LTS canonical lxd All versions
Ubuntu:Pro:24.04:LTS canonical incus All versions
Ubuntu:25.10 canonical incus All versions
Ubuntu:Pro:26.04:LTS canonical incus All versions
Original advisory text
Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed com...
Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write on the host, possibly leading to arbitrary command execution. Version 7.1.0 patches the issue.
Severity
9.9 Critical
CVSS 3.1: 9.9 (GHSA)
CVSS 3.1: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-20Improper Input Validation
Timeline
Published21 Aug 2026
Updated3 Sep 2026
First seen26 Jun 2026
Monitor software like this
Free during beta