Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-48755: Incus backup function can overwrite any file on server
CVE-2026-48755 · published 13 days ago
Summary
Incus lets users pick a program to compress backup data, but it only verifies the first word of the command. Extra options are not checked, so an attacker can add commands that cause the system to write files to any location, potentially allowing them to run their own code. Apply the latest Incus update that corrects this validation, or restrict who can set the backup compression setting.
What to do
- Update github.com lxc to version 7.2.0.
- Update lxc github.com/lxc/incus/v7 to version 7.2.0.
- Update debian incus to version 6.0.4-2+deb13u8.
- Update debian incus to version 7.0.0-5.
- Update debian lxd to version 5.0.2+git20231211.1364ae4-9+deb13u7.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | lxc | incus | < 7.2.0 |
| Debian:13 | debian | incus |
< 6.0.4-2+deb13u8 Fix: upgrade to 6.0.4-2+deb13u8
|
| Debian:14 | debian | incus |
< 7.0.0-5 Fix: upgrade to 7.0.0-5
|
| Debian:12 | debian | lxd | All versions |
| Debian:13 | debian | lxd |
< 5.0.2+git20231211.1364ae4-9+deb13u7 Fix: upgrade to 5.0.2+git20231211.1364ae4-9+deb13u7
|
| go | github.com | lxc |
< 7.2.0 Fix: upgrade to 7.2.0
|
| Go | lxc | github.com/lxc/incus | All versions |
| Go | lxc | github.com/lxc/incus/v6 | All versions |
| Go | lxc | github.com/lxc/incus/v7 |
< 7.2.0 Fix: upgrade to 7.2.0
|
| Ubuntu:Pro:16.04:LTS | canonical | lxd | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | lxd | All versions |
| Ubuntu:20.04:LTS | canonical | lxd | All versions |
| Ubuntu:Pro:24.04:LTS | canonical | incus | All versions |
| Ubuntu:25.10 | canonical | incus | All versions |
| Ubuntu:Pro:26.04:LTS | canonical | incus | All versions |
Original advisory text
Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed com...
Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write on the host, possibly leading to arbitrary command execution. Version 7.1.0 patches the issue.
References
- https://security-tracker.debian.org/tracker/CVE-2026-48755 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48755... Vendor Advisory
- https://github.com/advisories/GHSA-v6mj-8pf4-hhw4
- https://nvd.nist.gov/vuln/detail/CVE-2026-48755 Vendor Advisory
- https://github.com/lxc/incus/security/advisories/GHSA-v6mj-8pf4-hhw4 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-48755 Third Party Advisory
- https://github.com/canonical/lxd/pull/18597 Third Party Advisory
- https://github.com/lxc/incus/commit/873a032a461df6b09b7586435b592873863a4e88 Third Party Advisory
- https://ubuntu.com/security/CVE-2026-48755 Third Party Advisory
Severity
9.9
Critical
CVSS 3.1: 9.9 (GHSA)
CVSS 3.1: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-20Improper Input Validation
Timeline
Published21 Aug 2026
Updated3 Sep 2026
First seen26 Jun 2026
Sources
CVE-2026-48755 · OSV
GO-2026-5808 · OSV
CVE-2026-48755 · MITRE
DEBIAN-CVE-2026-48755 · OSV
UBUNTU-CVE-2026-48755 · OSV
GHSA-v6mj-8pf4-hhw4 · GHSA
CVE-2026-48755 · NVD
Monitor software like this
Free during beta